PT-2026-30688 · Brave Cms · Brave Cms

·

CVE-2026-35164

·

Published

2026-04-06

·

Updated

2026-04-06

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Brave CMS versions prior to 2.0.6
Description Brave CMS, an open-source CMS, contains an unrestricted file upload issue in the CKEditor upload functionality. The issue resides in the ckupload method within the app/Http/Controllers/Dashboard/CkEditorController.php file. The method does not validate uploaded file types, relying solely on user input. This allows an authenticated user to upload executable PHP scripts, potentially leading to Remote Code Execution.
Recommendations Update to version 2.0.6

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35164

Affected Products

Brave Cms