CVE-2026-41524

HIGH

Ajax30/BraveCMS-2.0: Stored XSS in Page / Article Content

Title source: cna
STIX 2.1

Description

Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verbatim in the database and subsequently rendered with Laravel Blade's unescaped output directive {!! !!}. Any JavaScript or HTML injected by an editor-role user is permanently stored and executed in every visitor's browser upon page load. This issue has been patched via commit 6c56603.

Scores

CVSS v3 8.7
EPSS 0.0021
EPSS Percentile 10.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
Ajax30/BraveCMS-2.0 < 6c5660373cf5f0ca9181603280427aca46ef11ea
Published May 08, 2026
Tracked Since May 08, 2026