CVE-2026-35047

Source
https://cve.org/CVERecord?id=CVE-2026-35047
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35047.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-35047
Aliases
  • GHSA-9rcc-w59j-965v
Published
2026-04-06T17:25:39.602Z
Modified
2026-07-18T03:41:50.599561321Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Brave CMS has Unrestricted File Upload in BraveCMS via CKEditor Endpoint
Details

Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitrary files, including executable scripts. This may lead to Remote Code Execution (RCE) on the server, potentially resulting in full system compromise, data exfiltration, or service disruption. All users running affected versions of BraveCMS are impacted. This vulnerability is fixed in 2.0.6.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35047.json",
    "cwe_ids": [
        "CWE-434"
    ],
    "cna_assigner": "GitHub_M",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "2.0.6"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/ajax30/bravecms-2.0

Affected ranges

Type
GIT
Repo
https://github.com/ajax30/bravecms-2.0
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35047.json"