baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Description
baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Blog posts feature. Version 5.1.2 fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
baserCMS prior to 5.1.2 contains a stored XSS in the Blog posts feature via improper slug handling in the article edit screen.
Vulnerability
Overview CVE-2024-46996 is a stored cross-site scripting (XSS) vulnerability in the Blog posts feature of baserCMS, a PHP-based website development framework. The root cause is improper handling of the 'slug' field in the article editing screen, allowing an attacker with administrative access to inject malicious scripts that are stored and later executed in the context of other users [1][2].
Attack
Vector and Prerequisites Exploitation requires an authenticated user with access to the article editing interface. The attack complexity is low, but the attacker must have sufficient privileges to create or edit blog posts. Since the vulnerability exists in the management screen, it primarily affects sites where the admin interface is accessible to multiple untrusted users [2][3].
Impact
If successfully exploited, an attacker can execute arbitrary JavaScript in the browser of any user viewing the affected blog post. This can lead to session hijacking, defacement, or theft of sensitive data within the context of the application. The stored XSS persists until the malicious input is removed [1][2].
Mitigation
The vulnerability is fixed in baserCMS version 5.1.2. Users running baserCMS 5.1.2 or earlier should update immediately. For baserCMS 4.x, version 4.8.2 (if released) may address similar issues; users are advised to check the vendor advisory. No workaround has been provided; updating is the recommended action [2][3].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
baserproject/basercmsPackagist | < 5.1.2 | 5.1.2 |
Affected products
2- baserproject/basercmsv5Range: < 5.1.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-66jv-qrm3-vvfgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-46996ghsaADVISORY
- basercms.net/security/JVN_00876083ghsax_refsource_MISCWEB
- github.com/baserproject/basercms/security/advisories/GHSA-66jv-qrm3-vvfgghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.