CVE-2026-61823
published 2026-09-24CVE-2026-61823: code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site…
PriorityP339high7.3CVSS 3.1
AVNACLPRLUIRSUCHIHAN
EPSS
0.21%
10.3th percentile
code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in the rich-text editor because the HTML sanitizer permits the `srcdoc` attribute on iframe elements. Although markup inside `srcdoc` is HTML-encoded during sanitization, browsers decode attribute entities before interpreting the iframe document, allowing an authenticated user with permission to edit an Editor field to store executable JavaScript that runs when another user views the content. Successful exploitation can result in session hijacking, unauthorized actions, account takeover, privilege escalation, or disclosure of administrative data. Version 9.22.5 patches the vulnerability by removing `srcdoc` from the permitted iframe attributes. As a workaround, applications that cannot upgrade should manually sanitize all Editor field content and remove every iframe `srcdoc` attribute before storing or rendering it.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code16 | sharp | < 9.22.5 | 9.22.5 |
| code16 | sharp | >= 0 < 9.22.5 | 9.22.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
ghsa·2026-09-25
CVE-2026-61823 [HIGH] CWE-79 code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
### Impact
A Stored Cross-Site Scripting (XSS) vulnerability exists in the rich text editor due to improper sanitization of the srcdoc attribute on elements.
While the underlying Symfony HtmlSanitizer correctly HTML-encodes special characters inside the attribute value (e.g., converting to ), the HTML specification mandates that browsers automatically decode HTML entities inside attribute values before processing them. As a result, any encoded JavaScript inside a srcdoc attribute is evaluated and executed as live HTML/JS in the context of the iframe when the page is rendered.
An attacker with permissions to edit an Editor field can inject malicious scripts to target other users viewing the content. Potential impacts inclu
VulDB
code16 Sharp up to 9.22.4 HTML Sanitizer srcdoc HTML injection
vuldb·2026-09-24·CVSS 7.3
CVE-2026-61823 [HIGH] code16 Sharp up to 9.22.4 HTML Sanitizer srcdoc HTML injection
A vulnerability marked as problematic has been reported in code16 Sharp up to 9.22.4. This affects an unknown part of the component HTML Sanitizer. The manipulation of the argument srcdoc leads to HTML injection.
This vulnerability is listed as CVE-2026-61823. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-24
Published