CVE WATCH / VULNERABILITY DETAIL

CVE-2026-97150

HIGHCVSS 7.2NVD feed

Published 30 September 2026 · tracked since 30 September 2026

Description

When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-97150 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-97150

HIGHCVSS 7.2NVD feed

Published 30 September 2026 · tracked since 30 September 2026

Description

When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]