CVE-2026-30940
Last modified
CVE-2026-30940 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. EPSS estimates a 1.05% chance of exploitation in the next 30 days.
Description
baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenticated administrator can include ../ sequences in the path parameter to create a PHP file in an arbitrary directory outside the theme directory, which may result in remote code execution (RCE). This issue has been patched in version 5.2.3.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Basercms | Basercms | < 5.2.3 |
References
- https://basercms.net/security/JVN_20837860Vendor Advisory
- https://github.com/baserproject/basercms/security/advisories/GHSA-c5c6-37vq-pjcqExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-30940?
How severe is CVE-2026-30940?
How do I fix CVE-2026-30940?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-30935ImageMagick is free and open-source software used for editin…4.4
- CVE-2026-30936ImageMagick is free and open-source software used for editin…5.5
- CVE-2026-30937ImageMagick is free and open-source software used for editin…6.1
- CVE-2026-30938Parse Server is an open source backend that can be deployed …5.3
- CVE-2026-30939Parse Server is an open source backend that can be deployed …7.5
- CVE-2026-3094Delta Electronics CNCSoft-G2 lacks proper validation of the …7.8
- CVE-2026-30941Parse Server is an open source backend that can be deployed …7.5
- CVE-2026-30942Flare is a Next.js-based, self-hostable file sharing platfor…6.5
- CVE-2026-30943Gokapi is a self-hosted file sharing server with automatic e…4.1
- CVE-2026-30944StudioCMS is a server-side-rendered, Astro native, headless …8.8
- CVE-2026-30945StudioCMS is a server-side-rendered, Astro native, headless …7.1
- CVE-2026-30946Parse Server is an open source backend that can be deployed …7.5
Are you affected by CVE-2026-30940?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
