CVE-2026-35047

Severity CVSS v4.0:
CRITICAL
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
06/04/2026
Last modified:
10/04/2026

Description

Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitrary files, including executable scripts. This may lead to Remote Code Execution (RCE) on the server, potentially resulting in full system compromise, data exfiltration, or service disruption. All users running affected versions of BraveCMS are impacted. This vulnerability is fixed in 2.0.6.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ajax30:bravecms:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.6 (excluding)