PublicCVE

CVE-2026-41524

HIGH8.7JSON exportCreate alert

Description

Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verbatim in the database and subsequently rendered with Laravel Blade's unescaped output directive {!! !!}. Any JavaScript or HTML injected by an editor-role user is permanently stored and executed in every visitor's browser upon page load. This issue has been patched via commit 6c56603.

CVSS breakdown

CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected products

  • Ajax30 / BraveCMS-2.0< 6c5660373cf5f0ca9181603280427aca46ef11ea – < 6c5660373cf5f0ca9181603280427aca46ef11ea