CVE-2026-97150
CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th
When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.
| Vendor | basercms users community |
| Product | bcaddonmigrator |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for basercms users community bcaddonmigrator
Be the first to know when new high vulnerabilities affecting basercms users community bcaddonmigrator are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Versions
baserCMS Users Community / BcAddonMigrator
0 โค 5.2.0