Published: 2026/07/31  Last Updated: 2026/07/31

Information from baserCMS Users Community

Vulnerability ID:JVNVU#94952030
Title:CSV file injection vulnerability in BaserCMS
Status:Vulnerable

This is a statement from the vendor itself with no modification by JPCERT/CC.

There is a CSV injection vulnerability in baserCMS.

### Target
baserCMS 5.2.8 and earlier versions

### Vulnerability
If this vulnerability is exploited, arbitrary scripts could be executed.

### Countermeasures
Update to the latest version of baserCMS

Please refer to the following page to reference for more information.
https://basercms.net/security/JVN_94952030

### Credits
- quanlna2 (Le Nguyen Anh Quan)
- namdi (Do Ich Nam)
- minhnn42 (Nguyen Ngoc Minh)
- VCSLab - Viettel Cyber Security