HIGH 8.6 NVD
CVE-2026-97150
When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is e
When converting baserCMS4-style addons to baserCMS5-style ones,
BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed.
Arbitrary files on the system may be read or deleted by an administrative user.
References
- https://basercms.net/security/JVN_21754394
- https://github.com/baserproject/BcAddonMigrator/commit/e836bc875e26910e1b5862f96cf280b4f06
- https://jvn.jp/en/jp/JVN21754394
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-09-30 via NVD.
vulnfeed aggregates 9449 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.