HarborGuard / CVE
Back to search
HIGHCVE-2026-41524Published Modified CNA GitHub_M

CVE-2026-41524: Ajax30/BraveCMS-2.0: Stored XSS in Page / Article Content

Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verbatim in the database and subsequently rendered with Laravel Blade's unescaped output directive {!! !!}. Any JavaScript or HTML injected by an editor-role user is permanently stored and executed in every visitor's browser upon page load. This issue has been patched via commit 6c56603.

Metrics

CVSS v3.1
8.7
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • Ajax30 / BraveCMS-2.0
    < 6c5660373cf5f0ca9181603280427aca46ef11ea
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CVE-2026-41524: Ajax30/BraveCMS-2.0: Stored XSS in Page / Article Content | HarborGuard CVE