PatchSiren

Ajax30 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Ajax30 CVE published 2026-04-06

CVE-2026-35183

An Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion feature of Brave CMS prior to 2.0.6. The vulnerability is located in the deleteImage method within the ArticleController.php file. An authenticated user with edit permissions can delete images attached to articles owned by other users. This could lead to unauthorized modification of article content. The vulnerabi [truncated]