Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2307 articles · 106035 vulns · 38/41 feeds (7d)
← Back to list
7.2
CVE-2026-30940EXPLOITEDPATCHED
baserproject · basercms

baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCE

Description

baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenticated administrator can include ../ sequences in the path parameter to create a PHP file in an arbitrary directory outside the theme directory, which may result in remote code execution (RCE). This issue has been patched in version 5.2.3.

Affected Products

VendorProductVersions
baserprojectbasercms< 5.2.3

References

  • https://github.com/baserproject/basercms/security/advisories/GHSA-c5c6-37vq-pjcq(x_refsource_CONFIRM)
  • https://basercms.net/security/JVN_20837860(x_refsource_MISC)
  • https://github.com/baserproject/basercms/releases/tag/5.2.3(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB5h ago
CVE-2026-30940 | baserproject basercms up to 5.2.2 Theme File Management API add.json path path traversal (GHSA-c5c6-37vq-pjcq)
→ No new info (linked only)
CVSS 3.17.2 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available5.2.3
CWECWE-22, CWE-73
PublishedMar 31, 2026
Last enriched4h agov2
Trending Score49
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-27697EXP
baserCMS: SQL injection vulnerability in blog post
Trending: 49
MEDIUMCVE-2026-32734EXP
baserCMS: Multiple vulnerabilities in baserCMS
Trending: 42
CRITICALCVE-2026-21861
baserCMS: OS Command Injection Leading to Remote Code Execution (RCE)
Trending: 30
CRITICALCVE-2026-30877
baserCMS: OS Command Injection in the baserCMS Update Functionality
Trending: 30
CRITICALCVE-2026-30878
baserCMS: Mail Form Acceptance Bypass via Public API
Trending: 30

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Mar 31, 2026
Discovered by ZDM
Mar 31, 2026
Actively Exploited
Mar 31, 2026
Patch Available
Mar 31, 2026
Updated: severity, activelyExploited, patchAvailable
Mar 31, 2026

Version History

v2
Last enriched 4h ago
v2Tier C4h ago

Updated severity to CRITICAL, marked as actively exploited, and specified the patch available as version 5.2.3.

severityactivelyExploitedpatchAvailable
via VulDB
v19h ago

Initial creation