CVE-2026-61825
published 2026-09-24CVE-2026-61825: code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site…
PriorityP344high8.7CVSS 3.1
AVNACLPRLUIRSCCHIHAN
EPSS
0.22%
11.3th percentile
code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in `SharpEditorFormField`: attacker-controlled content bearing the `data-html-content` attribute can bypass HTML sanitization and preserve executable markup, which may execute when another user views the stored content. The vendor identifies version 9.22.5 as patched; applications that intentionally enable `SharpFormEditorField::RAW_HTML` must continue to sanitize editor content themselves. As a workaround, applications should sanitize all editor content before storing or rendering it, for example with Symfony HtmlSanitizer, and disable RAW_HTML functionality where it is not required.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code16 | sharp | < 9.22.5 | 9.22.5 |
| code16 | sharp | >= 0 < 9.22.5 | 9.22.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
code16/sharp has a stored XSS via data-html-content Sanitizer Bypass
ghsa·2026-09-25
CVE-2026-61825 [HIGH] CWE-79 code16/sharp has a stored XSS via data-html-content Sanitizer Bypass
code16/sharp has a stored XSS via data-html-content Sanitizer Bypass
### Impact
The vulnerability allows an attacker to bypass the HTML sanitizer by using the `data-html-content` attribute in the content of a `SharpEditorFormField`.
### Patches
The field must now explicitly configure `SharpFormEditorField::RAW_HTML` in the toolbar to keep this behavior. **When using the `RAW_HTML` button, the application using `code16/sharp` must sanitize manually the content coming from the field**.
Vulnerability has been patched in version 9.22.5.
### Workarounds
Sanitize every contents of editors manually (e.g. using Symfony/HtmlSanitizer)
VulDB
code16 Sharp up to 9.22.4 SharpEditorFormField cross site scripting
vuldb·2026-09-24·CVSS 8.7
CVE-2026-61825 [HIGH] code16 Sharp up to 9.22.4 SharpEditorFormField cross site scripting
A vulnerability described as problematic has been identified in code16 Sharp up to 9.22.4. This vulnerability affects unknown code of the component SharpEditorFormField. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-61825. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-24
Published