
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30880 is an OS command injection vulnerability in the installer component of baserCMS, a PHP-based website development framework. The flaw affects baserCMS versions 5.2.2 and earlier, and was disclosed on March 30–31, 2026, with a patch released in version 5.2.3. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory, baserproject Advisory). The vulnerability was credited to researcher REN XINGDIAN and is tracked under GHSA-6hpg-8rx3-cwgv (GitHub Advisory).
The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), meaning the baserCMS installer fails to properly sanitize user-supplied input before passing it to OS-level command execution functions (GitHub Advisory). The attack vector is network-based, requires no authentication or user interaction, and no special privileges — however, exploitation requires that baserCMS has been deployed on a server but not yet completed the installation process (baserproject Advisory). The CVSS v4.0 rating notes High Attack Complexity, reflecting that the specific pre-installation state of the application must be present for exploitation to succeed. No public proof-of-concept code has been identified at this time (GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary OS commands on the affected server, resulting in full compromise of confidentiality, integrity, and availability of the vulnerable system (baserproject Advisory). This could enable unauthorized access to sensitive data stored on the server, modification or deletion of system files, installation of backdoors or malware, and potential lateral movement within the network (GitHub Advisory). The scope of impact is limited to the vulnerable system itself (no subsequent system impact per CVSS v4.0 metrics), but the ability to run arbitrary commands as the web server process makes this a severe risk for any organization with an uninstalled baserCMS instance exposed to the network.
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.057% (18th percentile), indicating a low near-term probability of exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. The key precondition — that baserCMS must be deployed but not yet installed — limits the attack surface to a relatively narrow window during initial setup.
/install or equivalent setup endpoint) to confirm the application is in the pre-installation state and the vulnerable installer component is accessible.;, |, &&, or backticks) embedded in installer form fields that are passed to OS command execution functions without proper sanitization./install, /setup) from external or unknown IP addresses; outbound connections from the web server to external hosts following installer access.;, |, &&, backticks); error logs showing unexpected command execution or shell process spawning./bin/sh, /bin/bash, curl, wget, python, nc) during or after installer access..php files with obfuscated content), cron job modifications, or SSH authorized_keys changes made by the web server user.The primary remediation is to update baserCMS to version 5.2.3 or later, which patches this vulnerability along with several other critical issues disclosed simultaneously (GitHub Release, GitHub Advisory). As an immediate workaround, organizations should implement network access controls to restrict access to the baserCMS installer endpoint to trusted IP addresses only, or take the installer offline if the application is not actively being set up. Any baserCMS instance that has been deployed but not yet installed should be treated as high-priority for patching or network isolation (baserproject Advisory).
The vulnerability was mentioned in a Loginsoft Medium post covering active exploits and supply chain attacks from late March to early April 2026, grouping it with other notable vulnerabilities of that period. Social media activity was observed on Bluesky and Mastodon (infosec.exchange) shortly after disclosure, primarily consisting of automated CVE notification posts. No significant independent researcher commentary or major media coverage specific to this CVE has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."