Ajax30

First CVE: Apr 6, 2026Active for: 1 yearTotal CVEs: 4

Ajax30's vulnerability profile centers on its BraveCMS product, a web content management system where identified weaknesses cluster around file-upload handling, authorization logic, and access controls. The recurring pattern of unrestricted file uploads, user-controlled authorization keys, and missing authorization checks reflects common risks in application-level access management and file-handling design. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ajax30 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 6, 2026
3 months ago
Most Recent CVE
Apr 6, 2026
109 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitrary files, including executable
Apr 6, 20269.831NONO
Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.php. The POST route for /rights
Apr 6, 20268.830NONO
Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found in app/Http/Controllers/Dashboar
Apr 6, 20268.830NONO
Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion feature. It is located in app/Http/Co
Apr 6, 20265.421NONO

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (75.0%)
High0 (0.0%)
None1 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ajax30.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ajax30 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ajax30's Products

Top CWEs