Executive brief
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
Affected products
- Packagist baserproject/basercms
Junglewise Threat Intelligence
CVE-2026-30940 · Severity: low · CVSS 3.1 · Published 2026-03-31
Technologies: baserproject/basercms (Packagist). Vendors: Packagist.
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API