Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found in app/Http/Controllers/Dashboard/CkEditorController.php within the ckupload method. The method fails to validate uploaded file types and relies entirely on user input. This allows an authenticated user to upload executable PHP scripts and gain Remote Code Execution. This vulnerability is fixed in 2.0.6.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ajax30
Ajax30 bravecms-2.0 |
|
| Vendors & Products |
Ajax30
Ajax30 bravecms-2.0 |
Mon, 06 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found in app/Http/Controllers/Dashboard/CkEditorController.php within the ckupload method. The method fails to validate uploaded file types and relies entirely on user input. This allows an authenticated user to upload executable PHP scripts and gain Remote Code Execution. This vulnerability is fixed in 2.0.6. | |
| Title | Brave CMS Sffected by Unrestricted File Upload via CKEditor Endpoint | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-04-06T17:33:33.715Z
Updated: 2026-04-07T14:07:00.606Z
Reserved: 2026-04-01T17:26:21.132Z
Link: CVE-2026-35164
Updated: 2026-04-07T14:06:51.071Z
Status : Undergoing Analysis
Published: 2026-04-06T18:16:42.900
Modified: 2026-04-07T15:17:42.303
Link: CVE-2026-35164
No data.