
DailyCVE@dailycve
🔵 Laravel: XSS in Debug Page Information - #CVE-2026-102279 (Low) -DC-Sep2026-2627 https://dailycve.com/laravel-xss-in-debug-page-information-cve-2026-102279-low-dc-sep2026-2627/
0000022
238 followersView on X
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hovers over the tooltip. This issue is fixed in versions 12.69.0 and 13.30.0.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🔵 Laravel: XSS in Debug Page Information - #CVE-2026-102279 (Low) -DC-Sep2026-2627 https://dailycve.com/laravel-xss-in-debug-page-information-cve-2026-102279-low-dc-sep2026-2627/