Security Research

CVEs & GHSAs discovered by our team

Public disclosures from the Pragma Core security research program. Every advisory below is a vulnerability our platform helped surface in real software, responsibly disclosed and patched.

14
Advisories
11
CVEs Assigned
14
GHSAs Issued
10
Critical / High
Read full advisory

Disclosure Timeline

Every advisory plotted chronologically. Hover to preview, click to read the full disclosure.

Drag to scroll · 14 entries

All Advisories

Filter by severity or tag to narrow the list. Each entry links to the full disclosure with technical details and references.

CVE-2026-62953 High

Path Traversal via Unsanitized Upload Filename

baserCMS plugin and theme upload handlers use the client-supplied filename to build a destination path without calling basename(), so an authenticated user can smuggle traversal sequences and write an arbitrary file, including a PHP payload, before any ZIP validation runs. If the webroot is writable this leads to remote code execution; the issue is fixed in version 5.2.3.

basercms
CVE-2026-62952 High

Arbitrary Binary Execution via Unvalidated PHP Path Parameter

The update_core admin action in baserCMS forwards the attacker-supplied php binary path to exec() through updateCore() and rollbackCore() without an allowlist check. Chained with a file-write primitive this gives authenticated remote code execution.

basercms
GHSA-7mvq-hwhc-c98g High

PHP Object Injection via Cache Deserialization

A PHP Object Injection vulnerability exists in the file-based cache backend due to insecure usage of PHP’s unserialize() function. Successful exploitation may allow remote code execution under the privileges of the web server user.

icms2
CVE-2026-46683 High

SSRF and local file read via the xsl-style-sheet option

This is a Server-Side Request Forgery (SSRF) and local file read vulnerability in KnpLabs Snappy, a PHP library that wraps wkhtmltopdf for HTML-to-PDF generation. The flaw lives in the xsl-style-sheet option, which is passed directly to wkhtmltopdf without any URL scheme validation. If an attacker can influence the value of that option, they can point it at internal network resources or at local files using file:// URIs, causing the server to fetch and embed content it should never expose.

Snappy
CVE-2026-46643 Medium

Binary path is never shell-escaped due to an inverted is_executable check

CVE-2026-46643 is a Moderate severity vulnerability in knplabs/knp-snappy (<= 1.7.0) where the binary path passed to Snappy's constructor is never shell-escaped before being executed, despite code that looks like it should be doing exactly that. The root cause is a logic inversion in the is_executable() check. escapeshellarg() wraps the path in single quotes, but is_executable() then looks for a file whose name literally contains those quote characters, which never exists.

Snappy
GHSA-87qc-37cw-84h4 Low

$temporaryFiles is public, enabling arbitrary file deletion at shutdown

GHSA-87qc-37cw-84h4 is a Low severity vulnerability in knplabs/knp-snappy (<= 1.7.1) where the $temporaryFiles property on AbstractGenerator is declared public instead of private. Snappy uses this array to track temp files it creates during generation, then deletes everything in it automatically when the object is destroyed at shutdown via __destruct().

Snappy
CVE-2026-45016 Medium

Local File Inclusion via file:// URI in Mail Compose

Mail composition handler processes image URLs found in outgoing HTML email bodies without validating their URI scheme

egroupware
CVE-2026-63672 Medium

Unrestricted Identity Provider Selection in SAML Authentication

Unauthenticated users can control the Identity Provider (IdP) selection in SAML authentication due to insufficient validation. This advisory explains the issue in Saml.php, the proof of concept, potential impact, and recommended remediation.

egroupware
CVE-2026-41524 High

Stored XSS in BraveCMS Page and Article Content

A stored Cross-Site Scripting (XSS) vulnerability in BraveCMS 2.0 allows attackers to inject malicious JavaScript into page or article content, which is executed in the browser of any user who views the affected page. This can lead to session hijacking, account takeover, or unauthorized actions performed on behalf of victims.

BraveCMS
CVE-2026-41576 High

Stored HTML Injection in Contact Email via nl2br() + Unescaped Blade Template

A stored HTML injection vulnerability has been identified in BraveCMS 2.0 that allows an unauthenticated remote attacker to inject arbitrary HTML markup into the email notification delivered to administrators through the public contact form.

BraveCMS
GHSA-j86p-76g3-4vcv Critical

Vulnerable Dependencies

BraveCMS 2.0 ships with a large set of out-of-date third-party libraries across both its PHP (Composer/Packagist) and JavaScript (npm) dependency trees. Multiple Critical and High severity vulnerabilities are present in the bundled versions, including the Laravel framework itself, Symfony components, Babel, Webpack, lodash, axios, and core cryptography packages.

BraveCMS
CVE-2026-35183 High

Insecure Direct Object Reference in Article Image Deletion

BraveCMS 2.0.0 contains an Insecure Direct Object Reference (IDOR) in the article image deletion endpoint. Any authenticated user with article-edit permissions can delete images attached to articles owned by other users by tampering with the filename and article ID in the URL.

BraveCMS
CVE-2026-35164 High

Unrestricted File Upload via CKEditor Endpoint

BraveCMS 2.0.0 contains an unrestricted file upload vulnerability in the CKEditor ckupload endpoint. Any authenticated user with at least Author privileges can upload an executable PHP file disguised as an image, then request it directly from the public web root to gain Remote Code Execution as the web server user.

BraveCMS
CVE-2026-35182 High

Missing Authorization Privilege Escalation

BraveCMS 2.0.0 ships with a missing authorization check on the user-role update endpoint, allowing any authenticated low-privileged user to promote their own account to Super Admin by sending a single crafted POST request.

BraveCMS
Arbitrary File Read 1 Authentication 1 Authentication Bypass 1 Blade Template 1 Broken Access Control 1 CMS Vulnerability 3 cms-security 1 Composer 3 cookie-theft 1 Email Injection 1 File Upload Bypass 1 HTML Injection 1 Identity Provider 1 IDOR 1 IdP Selection 1 Insecure Deserialization 1 Insecure Direct Object Reference 1 laravel 2 Local File Inclusion 1 Missing Authorization 1 Outdated Packages 1 Phishing 1 PHP 7 PHP Security 5 PHP Web Shell 1 Privilege Escalation 1 privilege-escalation 1 RCE 3 Remote Code Execution 1 SAML 1 Security Advisory 1 SimpleSAMLphp 1 SSO 1 ssrf 1 Supply Chain Security 1 Unrestricted File Upload 2 Vulnerable Dependencies 1 web 3 Web Application Security 5 web-security 1 xss 1

Start securing your codebase today

Connect your repositories and let AI agents handle continuous scanning, research, and triage.

Have questions? Get in touch →