CVE-2026-35164

Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found in app/Http/Controllers/Dashboard/CkEditorController.php within the ckupload method. The method fails to validate uploaded file types and relies entirely on user input. This allows an authenticated user to upload executable PHP scripts and gain Remote Code Execution. This vulnerability is fixed in 2.0.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ajax30:bravecms:*:*:*:*:*:*:*:*

History

14 Apr 2026, 15:51

Type Values Removed Values Added
First Time Ajax30
Ajax30 bravecms
CPE cpe:2.3:a:ajax30:bravecms:*:*:*:*:*:*:*:*
References () https://github.com/Ajax30/BraveCMS-2.0/security/advisories/GHSA-2j4q-6p52-4rhw - () https://github.com/Ajax30/BraveCMS-2.0/security/advisories/GHSA-2j4q-6p52-4rhw - Exploit, Vendor Advisory

07 Apr 2026, 15:17

Type Values Removed Values Added
References () https://github.com/Ajax30/BraveCMS-2.0/security/advisories/GHSA-2j4q-6p52-4rhw - () https://github.com/Ajax30/BraveCMS-2.0/security/advisories/GHSA-2j4q-6p52-4rhw -

06 Apr 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-06 18:16

Updated : 2026-04-14 15:51


NVD link : CVE-2026-35164

Mitre link : CVE-2026-35164

CVE.ORG link : CVE-2026-35164


JSON object : View

Products Affected

ajax30

  • bravecms
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type