Back to all advisories

Tag: Web Application Security

5 advisories tagged with "Web Application Security".

CVE-2026-45016 Medium

Local File Inclusion via file:// URI in Mail Compose

Mail composition handler processes image URLs found in outgoing HTML email bodies without validating their URI scheme

egroupware
CVE-2026-41576 High

Stored HTML Injection in Contact Email via nl2br() + Unescaped Blade Template

A stored HTML injection vulnerability has been identified in BraveCMS 2.0 that allows an unauthenticated remote attacker to inject arbitrary HTML markup into the email notification delivered to administrators through the public contact form.

BraveCMS
CVE-2026-35183 High

Insecure Direct Object Reference in Article Image Deletion

BraveCMS 2.0.0 contains an Insecure Direct Object Reference (IDOR) in the article image deletion endpoint. Any authenticated user with article-edit permissions can delete images attached to articles owned by other users by tampering with the filename and article ID in the URL.

BraveCMS
CVE-2026-35164 High

Unrestricted File Upload via CKEditor Endpoint

BraveCMS 2.0.0 contains an unrestricted file upload vulnerability in the CKEditor ckupload endpoint. Any authenticated user with at least Author privileges can upload an executable PHP file disguised as an image, then request it directly from the public web root to gain Remote Code Execution as the web server user.

BraveCMS
CVE-2026-35182 High

Missing Authorization Privilege Escalation

BraveCMS 2.0.0 ships with a missing authorization check on the user-role update endpoint, allowing any authenticated low-privileged user to promote their own account to Super Admin by sending a single crafted POST request.

BraveCMS

Start securing your codebase today

Connect your repositories and let AI agents handle continuous scanning, research, and triage.

Have questions? Get in touch →