[Japanese]

JVNDB-2026-026396

CSV file injection vulnerability in BaserCMS

Overview

BaserCMS provided by baserCMS Users Community contains the following vulnerability.
  • Improper neutralization of formula elements in a CSV file (CWE-1236) - CVE-2026-65875
This vulnerability was reported by the following persons to JPCERT/CC. JPCERT/CC coordinated with the developer.

VCSLab - Viettel Cyber Security quanlna2 (Le Nguyen Anh Quan)
VCSLab - Viettel Cyber Security namdi (Do Ich Nam)
VCSLab - Viettel Cyber Security minhnn42 (Nguyen Ngoc Minh)
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 7.1 (High) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Scope: Changed
  • Confidentiality Impact: Low
  • Integrity Impact: Low
  • Availability Impact: Low
Affected Products


baserCMS Users Community
  • baserCMS versions prior to 5.3.0

Impact

If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.
Solution

[Update the Software]
Update the software to the latest version according to the information provided by the developer.
Vendor Information

baserCMS Users Community
CWE (What is CWE?)

  1. Improper Neutralization of Formula Elements in a CSV File(CWE-1236) [Other]
CVE (What is CVE?)

  1. CVE-2026-65875
References

  1. JVN : JVNVU#94952030
Revision History

  • [2026/08/04]
      Web page was published