Back to all advisories

Tag: Vulnerable Dependencies

1 advisory tagged with "Vulnerable Dependencies".

GHSA-j86p-76g3-4vcv Critical

Vulnerable Dependencies

BraveCMS 2.0 ships with a large set of out-of-date third-party libraries across both its PHP (Composer/Packagist) and JavaScript (npm) dependency trees. Multiple Critical and High severity vulnerabilities are present in the bundled versions, including the Laravel framework itself, Symfony components, Babel, Webpack, lodash, axios, and core cryptography packages.

BraveCMS

Start securing your codebase today

Connect your repositories and let AI agents handle continuous scanning, research, and triage.

Have questions? Get in touch →