| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8cr7-r8qw-gp3c | baserCMS has Mail Form Acceptance Bypass via Public API |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Basercms
Basercms basercms |
|
| CPEs | cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Basercms
Basercms basercms |
Tue, 31 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. This issue has been patched in version 5.2.3. | |
| Title | baserCMS: Mail Form Acceptance Bypass via Public API | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-31T19:09:18.507Z
Reserved: 2026-03-06T00:04:56.699Z
Link: CVE-2026-30878
Updated: 2026-03-31T19:05:35.231Z
Status : Analyzed
Published: 2026-03-31T01:16:35.977
Modified: 2026-04-01T20:28:15.140
Link: CVE-2026-30878
No data.
OpenCVE Enrichment
Updated: 2026-03-31T19:56:40Z
Github GHSA