Back to all advisories

Tag: Blade Template

1 advisory tagged with "Blade Template".

CVE-2026-41576 High

Stored HTML Injection in Contact Email via nl2br() + Unescaped Blade Template

A stored HTML injection vulnerability has been identified in BraveCMS 2.0 that allows an unauthenticated remote attacker to inject arbitrary HTML markup into the email notification delivered to administrators through the public contact form.

BraveCMS

Start securing your codebase today

Connect your repositories and let AI agents handle continuous scanning, research, and triage.

Have questions? Get in touch →