Public disclosures from the Pragma Core security research program. Every advisory below is a vulnerability our platform helped surface in real software, responsibly disclosed and patched.
Every advisory plotted chronologically. Hover to preview, click to read the full disclosure.
Filter by severity or tag to narrow the list. Each entry links to the full disclosure with technical details and references.
baserCMS plugin and theme upload handlers use the client-supplied filename to build a destination path without calling basename(), so an authenticated user can smuggle traversal sequences and write an arbitrary file, including a PHP payload, before any ZIP validation runs. If the webroot is writable this leads to remote code execution; the issue is fixed in version 5.2.3.
The update_core admin action in baserCMS forwards the attacker-supplied php binary path to exec() through updateCore() and rollbackCore() without an allowlist check. Chained with a file-write primitive this gives authenticated remote code execution.
A PHP Object Injection vulnerability exists in the file-based cache backend due to insecure usage of PHP’s unserialize() function. Successful exploitation may allow remote code execution under the privileges of the web server user.
This is a Server-Side Request Forgery (SSRF) and local file read vulnerability in KnpLabs Snappy, a PHP library that wraps wkhtmltopdf for HTML-to-PDF generation. The flaw lives in the xsl-style-sheet option, which is passed directly to wkhtmltopdf without any URL scheme validation. If an attacker can influence the value of that option, they can point it at internal network resources or at local files using file:// URIs, causing the server to fetch and embed content it should never expose.
CVE-2026-46643 is a Moderate severity vulnerability in knplabs/knp-snappy (<= 1.7.0) where the binary path passed to Snappy's constructor is never shell-escaped before being executed, despite code that looks like it should be doing exactly that. The root cause is a logic inversion in the is_executable() check. escapeshellarg() wraps the path in single quotes, but is_executable() then looks for a file whose name literally contains those quote characters, which never exists.
GHSA-87qc-37cw-84h4 is a Low severity vulnerability in knplabs/knp-snappy (<= 1.7.1) where the $temporaryFiles property on AbstractGenerator is declared public instead of private. Snappy uses this array to track temp files it creates during generation, then deletes everything in it automatically when the object is destroyed at shutdown via __destruct().
Mail composition handler processes image URLs found in outgoing HTML email bodies without validating their URI scheme
Unauthenticated users can control the Identity Provider (IdP) selection in SAML authentication due to insufficient validation. This advisory explains the issue in Saml.php, the proof of concept, potential impact, and recommended remediation.
A stored Cross-Site Scripting (XSS) vulnerability in BraveCMS 2.0 allows attackers to inject malicious JavaScript into page or article content, which is executed in the browser of any user who views the affected page. This can lead to session hijacking, account takeover, or unauthorized actions performed on behalf of victims.
A stored HTML injection vulnerability has been identified in BraveCMS 2.0 that allows an unauthenticated remote attacker to inject arbitrary HTML markup into the email notification delivered to administrators through the public contact form.
BraveCMS 2.0 ships with a large set of out-of-date third-party libraries across both its PHP (Composer/Packagist) and JavaScript (npm) dependency trees. Multiple Critical and High severity vulnerabilities are present in the bundled versions, including the Laravel framework itself, Symfony components, Babel, Webpack, lodash, axios, and core cryptography packages.
BraveCMS 2.0.0 contains an Insecure Direct Object Reference (IDOR) in the article image deletion endpoint. Any authenticated user with article-edit permissions can delete images attached to articles owned by other users by tampering with the filename and article ID in the URL.
BraveCMS 2.0.0 contains an unrestricted file upload vulnerability in the CKEditor ckupload endpoint. Any authenticated user with at least Author privileges can upload an executable PHP file disguised as an image, then request it directly from the public web root to gain Remote Code Execution as the web server user.
BraveCMS 2.0.0 ships with a missing authorization check on the user-role update endpoint, allowing any authenticated low-privileged user to promote their own account to Super Admin by sending a single crafted POST request.
Connect your repositories and let AI agents handle continuous scanning, research, and triage.
Choose which categories you are happy to allow. You can change your mind at any time using the Cookie settings link in the footer.