Back to all advisories

Tag: laravel

2 advisories tagged with "laravel".

CVE-2026-41576 High

Stored HTML Injection in Contact Email via nl2br() + Unescaped Blade Template

A stored HTML injection vulnerability has been identified in BraveCMS 2.0 that allows an unauthenticated remote attacker to inject arbitrary HTML markup into the email notification delivered to administrators through the public contact form.

BraveCMS
CVE-2026-35183 High

Insecure Direct Object Reference in Article Image Deletion

BraveCMS 2.0.0 contains an Insecure Direct Object Reference (IDOR) in the article image deletion endpoint. Any authenticated user with article-edit permissions can delete images attached to articles owned by other users by tampering with the filename and article ID in the URL.

BraveCMS

Start securing your codebase today

Connect your repositories and let AI agents handle continuous scanning, research, and triage.

Have questions? Get in touch →