BaserCMS CSV Injection Vulnerability Disclosed

BaserCMS CSV Injection Vulnerability Disclosed

First seen 3 Aug 2026, 14:53 UTC Thehackerwirebasercms.netjvn.jpwww.cvedetails.com 86% similarity 64.5

Article Content

Browse articles
ThreatCluster

BaserCMS versions prior to 5.3.0 contain a CSV file injection vulnerability identified as CVE-2026-65875. This flaw allows attackers to inject malicious code into CSV files, which may execute when opened by users. The vulnerability affects all users of BaserCMS who download and open these compromised files. The CVSS score for this vulnerability is 7.1, indicating a high severity level. The issue was reported by multiple researchers from VCSLab and coordinated with JPCERT/CC. Users are advised to update their software to the latest version to mitigate risks. The vulnerability was published on August 3, 2026.

Key Points: • BaserCMS versions before 5.3.0 are vulnerable to CSV file injection. • CVE-2026-65875 has a CVSS score of 7.1, indicating high severity. • Users are urged to update their software to prevent exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-08-03
CVE-2026-65875 published
BaserCMS disclosed a CSV file injection vulnerability affecting versions prior to 5.3.0.
jvn.jp
2026-08-03
Vulnerability reported
The vulnerability was reported by researchers from VCSLab and coordinated with JPCERT/CC.
jvn.jp
2026-08-03
Advisory issued
Users are advised to update to the latest version to mitigate the risk of exploitation.
Thehackerwire

Community

Browse all →

Tracked Entities in This Story