CVE-2026-30878 Details
Description
baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. This issue has been patched in version 5.2.3.
A vulnerability in baserCMS versions prior to 5.2.3 allows unauthenticated users to bypass mail form acceptance controls through a public API. This issue enables unauthorized submissions via the Mail API, even when forms are not accepting entries, potentially leading to spam or abuse. The vulnerability arises because the API endpoint does not check the form's acceptance status, a control that is enforced in the user interface.
Users are advised to update baserCMS to version 5.2.3 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/baserproject/basercms/security/advisories/GHSA-8cr7-r8qw-gp3c | CISA-ADP | ExploitVendor Advisory |
| https://basercms.net/security/JVN_20837860 | [email protected] | Vendor Advisory |
| https://github.com/baserproject/basercms/releases/tag/5.2.3 | [email protected] | Release Notes |
| https://github.com/baserproject/basercms/security/advisories/GHSA-8cr7-r8qw-gp3c | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| basercms basercms | < 5.2.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2026 | Initial Analysis | [email protected] |
| Mar 31, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | New CVE Received | [email protected] |