1. CSVインジェクション(数式インジェクション):CVE-2026-65875 2. BcDatabaseServiceにおけるSQLインジェクション 3. Blog Tags APIにおける未認証SQLインジェクション(ORDER BY):CVE-2026-62951 4. 検証不十分なPHPパスパラメータを介した任意のバイナリ実行:CVE-2026-62952 5. サニタイズされていないアップロードファイル名によるパス・トラバーサル:CVE-2026-62953 6. サニタイズされていないsort/direction/conditionsパラメータを介したAdmin APIでのSQLインジェクション:CVE-2026-59872 7. Theme File APIにおけるパス・トラバーサル:CVE-2026-62954 8. BcThemeFileServiceにおけるrealpath()を介したパス・トラバーサル:CVE-2026-62955 9. BlogTagsServiceにおけるORDER BYを介したSQLインジェクション:CVE-2026-62950 10. MailMessagesServiceにおけるORDER BYを介したSQLインジェクション:CVE-2026-62956 11. セッション認証フォールバックの悪用による、`Api/Admin`エンドポイントでの認可回避:CVE-2026-63012 12. データベース復元機能を介したリモートコード実行
1、4、5、7、8、9については管理画面を不特定多数のユーザーに利用させている場合のみに対応が必要となる脆弱性です。
baserCMSの最新バージョンにアップデートを行う
=========================================================================
baserCMS has multiple vulnerabilities including CSV Injection. If you are affected by this issue, please update to the new version as soon as possible.
baserCMS 5.0.0 - 5.2.8
If these vulnerabilities are exploited, arbitrary scripts may be executed.
1. CSV Injection (Formula Injection):CVE-2026-65875 2. SQL Injection + Code Execution in baserCMS BcDatabaseService 3. Unauthenticated SQL injection (ORDER BY) in Blog Tags API :CVE-2026-62951 4. Arbitrary Binary Execution via Unvalidated PHP Path Parameter:CVE-2026-62952 5. Path Traversal via Unsanitized Upload Filename:CVE-2026-62953 6. SQL Injection in Admin API via unsanitized sort/direction/conditions parameters:CVE-2026-59872 7. Path Traversal in Theme File API:CVE-2026-62954 8. Path Traversal Bypass via realpath() in BcThemeFileService:CVE-2026-62955 9. SQL Injection via ORDER BY in BlogTagsService:CVE-2026-62950 10. SQL Injection via ORDER BY in MailMessagesService:CVE-2026-62956 11. Authorization bypass of all `Api/Admin` endpoints configured with `auth => true` via session authentication fallback abuse:CVE-2026-63012 12. Remote Code Execution via Database Restore Feature
Update to the latest version of baserCMS
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
