Published: 2026/09/25  Last Updated: 2026/09/25

Information from baserCMS Users Community

Vulnerability ID:JVN#14353754
Title:Multiple vulnerabilities in baserCMS
Status:Vulnerable

This is a statement from the vendor itself with no modification by JPCERT/CC.

baserCMS contains multiple vulnerabilities.

### Target
baserCMS 5.4.0 and earlier versions

### Vulnerability
The product contains the following multiple vulnerabilities.

- CVE-2026-93460: An attacker who is logged in with permission to edit mail form fields may execute an arbitrary script on the web browser of a user who views the form.
- CVE-2026-93462: An unauthenticated remote attacker may obtain non-public information about blog comments, such as the content of comments awaiting approval and the email addresses of commenters.
- CVE-2026-93463: An attacker who is logged in with permission to edit articles may bypass the script input restriction and execute an arbitrary script on the web browser of a user who views the article.
- CVE-2026-93464: An attacker who is logged in with permission to edit custom content settings may execute an arbitrary script on the web browser of a user who views the public page.

### Countermeasures
Update baserCMS to version 5.4.1 or 5.3.1 or later.

Please refer to the following page for more information.
https://basercms.net/security/JVN_14353754

### Credits
CVE-2026-93460: Sou Katou@Mitsui Bussan Secure Directions, Inc.
CVE-2026-93462: Yuji Tounai@Mitsui Bussan Secure Directions, Inc.
CVE-2026-93463: Gai Tanaka@Mitsui Bussan Secure Directions, Inc.
CVE-2026-93464: Kuniyoshi Noguchi@Mitsui Bussan Secure Directions, Inc.