Back to all advisories

Tag: Remote Code Execution

1 advisory tagged with "Remote Code Execution".

CVE-2026-35164 High

Unrestricted File Upload via CKEditor Endpoint

BraveCMS 2.0.0 contains an unrestricted file upload vulnerability in the CKEditor ckupload endpoint. Any authenticated user with at least Author privileges can upload an executable PHP file disguised as an image, then request it directly from the public web root to gain Remote Code Execution as the web server user.

BraveCMS

Start securing your codebase today

Connect your repositories and let AI agents handle continuous scanning, research, and triage.

Have questions? Get in touch →