
🔴 code16/sharp, Stored XSS via data-#html-content Sanitizer Bypass, #CVE-2026-61825, High -DC-Sep2026-2582 https://dailycve.com/code16-sharp-stored-xss-via-data-html-content-sanitizer-bypass-cve-2026-61825-high-dc-sep2026-2582/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in `SharpEditorFormField`: attacker-controlled content bearing the `data-html-content` attribute can bypass HTML sanitization and preserve executable markup, which may execute when another user views the stored content. The vendor identifies version 9.22.5 as patched; applications that intentionally enable `SharpFormEditorField::RAW_HTML` must continue to sanitize editor content themselves. As a workaround, applications should sanitize all editor content before storing or rendering it, for example with Symfony HtmlSanitizer, and disable RAW_HTML functionality where it is not required.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🔴 code16/sharp, Stored XSS via data-#html-content Sanitizer Bypass, #CVE-2026-61825, High -DC-Sep2026-2582 https://dailycve.com/code16-sharp-stored-xss-via-data-html-content-sanitizer-bypass-cve-2026-61825-high-dc-sep2026-2582/