CVE-2026-30940 | baserproject basercms up to 5.2.2 Theme File Management API add.json path path traversal (GHSA-c5c6-37vq-pjcq)
A vulnerability, which was classified as critical, has been found in baserproject basercms up to 5.2.2. Affected by this vulnerability is an unknown functionality of the file /baser/api/admin/bc-theme-file/theme_files/add.json of the component Theme File Management API. The manipulation of the argument path leads to path traversal.
This vulnerability is traded as CVE-2026-30940. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.