HIGH
Ajax30
CVE published 2026-04-06
CVE-2026-35183
An Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion feature of Brave CMS prior to 2.0.6. The vulnerability is located in the deleteImage method within the ArticleController.php file. An authenticated user with edit permissions can delete images attached to articles owned by other users. This could lead to unauthorized modification of article content. The vulnerabi [truncated]