Published:2026/09/25  Last Updated:2026/09/25

JVN#14353754
Multiple vulnerabilities in baserCMS

Overview

baserCMS provided by baserCMS User Community contains multiple vulnerabilities.

Products Affected

CVE-2026-93460, CVE-2026-93462, CVE-2026-93463, CVE-2026-93464

  • baserCMS versions prior to 5.4.1 (5.4 series)
  • baserCMS versions prior to 5.3.1 (Includes all versions prior to 5.3 series)
CVE-2026-62956
  • baserCMS versions prior to 5.2.10 (Includes all versions prior to 5.2 series)

Description

baserCMS provided by baserCMS User Community contains multiple vulnerabilities listed below:

  • Cross-site scripting (CWE-79)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N Base Score 5.1
    • CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Base Score 5.4
    • CVE-2026-93460, CVE-2026-93463, CVE-2026-93464
  • SQL injection (CWE-89)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N Base Score 5.3
    • CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L Base Score 6.3
    • CVE-2026-62956
  • Missing authentication for critical function (CWE-306)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 6.9
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score 5.3
    • CVE-2026-93462

Impact

  • An arbitrary script may be executed in the user's web browser (CVE-2026-93460, CVE-2026-93463, CVE-2026-93464).
  • Information stored in the product's database may be obtained or tampered with by an attacker who has credentials of the Web API (CVE-2026-62956).
  • A remote attacker may obtain sensitive information (CVE-2026-93462).

Solution

Update the Softwere
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
baserCMS Users Community Vulnerable 2026/09/25 baserCMS Users Community website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

CVE-2026-93460
So Kato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2026-62956, CVE-2026-93462
Yuji Tounai of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2026-93463
Gai Tanaka of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2026-93464
Kuniyoshi Noguchi (KuniNogu) of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-93464
CVE-2026-93463
CVE-2026-93462
CVE-2026-93460
JVN iPedia JVNDB-2026-000141