Back to all advisories

Tag: Composer

3 advisories tagged with "Composer".

CVE-2026-62953 High

Path Traversal via Unsanitized Upload Filename

baserCMS plugin and theme upload handlers use the client-supplied filename to build a destination path without calling basename(), so an authenticated user can smuggle traversal sequences and write an arbitrary file, including a PHP payload, before any ZIP validation runs. If the webroot is writable this leads to remote code execution; the issue is fixed in version 5.2.3.

basercms
CVE-2026-62952 High

Arbitrary Binary Execution via Unvalidated PHP Path Parameter

The update_core admin action in baserCMS forwards the attacker-supplied php binary path to exec() through updateCore() and rollbackCore() without an allowlist check. Chained with a file-write primitive this gives authenticated remote code execution.

basercms
GHSA-j86p-76g3-4vcv Critical

Vulnerable Dependencies

BraveCMS 2.0 ships with a large set of out-of-date third-party libraries across both its PHP (Composer/Packagist) and JavaScript (npm) dependency trees. Multiple Critical and High severity vulnerabilities are present in the bundled versions, including the Laravel framework itself, Symfony components, Babel, Webpack, lodash, axios, and core cryptography packages.

BraveCMS

Start securing your codebase today

Connect your repositories and let AI agents handle continuous scanning, research, and triage.

Have questions? Get in touch →