CVE-2026-35164 | Ajax30 BraveCMS up to 2.0.5 CkEditorController.php unrestricted upload (GHSA-2j4q-6p52-4rhw)
A vulnerability has been found in Ajax30 BraveCMS up to 2.0.5 and classified as critical. This impacts an unknown function of the file app/Http/Controllers/Dashboard/CkEditorController.php. Performing a manipulation results in unrestricted upload.
This vulnerability is reported as CVE-2026-35164. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.