PT-2026-30688 · Brave Cms · Brave Cms

Para213

·

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-35164

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Brave CMS versions prior to 2.0.6
Description Brave CMS, an open-source CMS, contains an unrestricted file upload issue in the CKEditor upload functionality. The issue resides in the ckupload method within the app/Http/Controllers/Dashboard/CkEditorController.php file. The method does not validate uploaded file types, relying solely on user input. This allows an authenticated user to upload executable PHP scripts, potentially leading to Remote Code Execution.
Recommendations Update to version 2.0.6

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-35164

Affected Products

Brave Cms