PatchSiren

baserproject CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH baserproject CVE published 2026-08-20

CVE-2026-76635

The CVE-2026-76635 vulnerability is a SQL injection flaw in baserCMS before version 5.3.0, located in BcDatabaseService.php. Authenticated administrators can exploit this vulnerability to inject malicious SQL table names and configuration values. A backup restore code injection flaw exists, allowing attackers to plant malicious table names and trigger error-based SQL injection to retrieve database informa [truncated]