PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65875 baserCMS Users Community CVE debrief

BaserCMS, provided by the baserCMS Users Community, contains a CSV file injection vulnerability. This vulnerability allows an attacker to inject malicious code into a CSV file, which can be executed if a user downloads and opens the file. The CVE record was published on 2026-08-03T01:16:45.657Z and has not been modified since then. The affected product is BaserCMS. The CVSS score for this vulnerability is 5.1, indicating a medium severity level. Users of BaserCMS, administrators of systems using BaserCMS, and security teams responsible for vulnerability management should take necessary actions to verify inventory for BaserCMS installations, restrict download and execution of CSV files from untrusted sources, and monitor for suspicious CSV file downloads and modifications.

Vendor
baserCMS Users Community
Product
BaserCMS
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-08-03
Advisory published
2026-08-03
Advisory updated
2026-08-03

Who should care

Users of BaserCMS, administrators of systems using BaserCMS, and security teams responsible for vulnerability management should take necessary actions to verify inventory for BaserCMS installations, restrict download and execution of CSV files from untrusted sources, and monitor for suspicious CSV file downloads and modifications. This vulnerability has a CVSS score of 5.1 and is classified as MEDIUM severity, indicating a medium priority for remediation.

Technical summary

BaserCMS contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed. This vulnerability has a CVSS score of 5.1 and is classified as MEDIUM severity. The affected product is BaserCMS, and users of BaserCMS, administrators of systems using BaserCMS, and security teams responsible for vulnerability management should take necessary actions.

Defensive priority

Medium priority given the CVSS score of 5.1 and potential for code execution.

Recommended defensive actions

  • Verify inventory for BaserCMS installations
  • Restrict download and execution of CSV files from untrusted sources
  • Monitor for suspicious CSV file downloads and modifications
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

Evidence is limited; primary official records indicate a CSV file injection vulnerability in BaserCMS. Verification of affected scope and vendor remediation is needed. The CVE record was published on 2026-08-03T01:16:45.657Z and has not been modified since then. Additional verification tasks are required to confirm the affected systems and validate vendor guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T01:16:45.657Z and has not been modified since then.