Executive brief
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
Affected products
- Packagist baserproject/basercms
Junglewise Threat Intelligence
CVE-2026-21861 · Severity: low · CVSS 3.1 · Published 2026-03-31
Technologies: baserproject/basercms (Packagist). Vendors: Packagist.
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)