cbcvebase.

Code16 Sharp vulnerabilities

13 known vulnerabilities affecting code16/sharp.

Total CVEs
13
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH9MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2023-4863P1HIGHCVSS 8.8KEVPoC≥ 0, < 0.32.62023-11-16
CVE-2023-4863 [HIGH] sharp vulnerability in libwebp dependency CVE-2023-4863 sharp vulnerability in libwebp dependency CVE-2023-4863 ## Overview sharp uses libwebp to decode WebP images and versions prior to the latest 0.32.6 are vulnerable to the high severity https://github.com/advisories/GHSA-j7hp-h8jx-5ppr. ## Who does this affect? Almost anyone processing untrusted input with versions of sharp prior to 0.32.6. ## How to resolve this? ### Using prebuilt binaries provided by sharp? Mos
ghsaosv
CVE-2026-33687P2HIGHCVSS 8.8fixed in 9.20.02026-03-26
CVE-2026-33687 [HIGH] CWE-434 CVE-2026-33687: Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 con Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability in the file upload endpoint that allows authenticated users to bypass all file type restrictions. The upload endpoint within the `ApiFormUploadController` accepts a client-controlled `validation_rule` parameter. This parameter is di
ghsanvdosv
CVE-2026-33686P3HIGHCVSS 8.8fixed in 9.20.02026-03-26
CVE-2026-33686 [HIGH] CWE-22 CVE-2026-33686: Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 hav Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal vulnerability in the FileUtil class. The application fails to sanitize file extensions properly, allowing path separators to be passed into the storage layer. In `src/Utils/FileUtil.php`, the `FileUtil::explodeExtension()` function ext
ghsanvdosv
CVE-2026-84383P3HIGH≥ 0, < 0.35.42026-09-08
CVE-2026-84383 [HIGH] CWE-122 sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545 sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545 ### Impact A number of vulnerabilities, two rated as "Critical" severity using CVSSv3, have been discovered and fixed in the upstream libheif dependency. These can lead to possible remote code execution (RCE) on glibc-based Linux when run under certain conditions. The attack vector for these claims to be "net
ghsa
CVE-2026-44692P3HIGHCVSS 7.7fixed in 9.22.02026-06-10
CVE-2026-44692 [HIGH] CWE-639 CVE-2026-44692: Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sha Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic download endpoint that authorizes access only to the supplied Sharp entity instance, but then reads the target storage disk and path from request parameters. Because the requested storage object is not bound to the authorized entity
ghsanvd
CVE-2026-61825P3HIGHCVSS 8.7fixed in 9.22.52026-09-24
CVE-2026-61825 [HIGH] CWE-79 CVE-2026-61825: code16 Sharp is a Laravel-based framework for building content-management and administrative interfa code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in `SharpEditorFormField`: attacker-controlled content bearing the `data-html-content` attribute can bypass HTML sanitization and preserve executable markup, which may execut
ghsanvd
CVE-2026-33327P3HIGHCVSS 7.0≥ 0, < 0.35.02026-07-21
CVE-2026-33327 [HIGH] CWE-1395 sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591 sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591 ### Impact A number of vulnerabilities, two rated as "High" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency. Those processing untrusted input with versions of sharp prior to 0.35.0 are affected. ### Patches ##
ghsa
CVE-2026-96889P3HIGHCVSS 7.8≥ 0, < 0.35.52026-10-06
CVE-2026-96889 [HIGH] CWE-1395 sharp : Vulnerability in librsvg dependency CVE-2026-96889 sharp : Vulnerability in librsvg dependency CVE-2026-96889 ### Impact A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux. ### Patches #### Using prebuilt binaries provided by sharp? Most people rely on the prebuilt binarie
ghsa
CVE-2026-61823P3HIGHCVSS 7.3fixed in 9.22.52026-09-24
CVE-2026-61823 [HIGH] CWE-79 CVE-2026-61823: code16 Sharp is a Laravel-based framework for building content-management and administrative interfa code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in the rich-text editor because the HTML sanitizer permits the `srcdoc` attribute on iframe elements. Although markup inside `srcdoc` is HTML-encoded during sanitization, bro
ghsanvd
CVE-2022-29256P4MEDIUM≥ 0, < 0.30.52022-06-01
CVE-2022-29256 [MEDIUM] CWE-77 sharp vulnerable to Command Injection in post-installation over build environment sharp vulnerable to Command Injection in post-installation over build environment There's a possible vulnerability in logic that is run only at `npm install` time when installing versions of `sharp` prior to the latest v0.30.5. This is not part of any runtime code, does not affect Windows users at all, and is unlikely to affect anyone that already cares about the security of their b
ghsaosv
CVE-2025-62798P4MEDIUMCVSS 5.4fixed in 9.11.12025-10-28
CVE-2025-62798 [MEDIUM] CWE-79 CVE-2025-62798: Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Sit Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vulnerability was discovered in code16/sharp when rendering content using the SharpShowTextField component. In affected versions, expressions wrapped in {{ & }} were evaluated by Vue. This allowed attackers to inject arbitrary JavaScr
ghsanvdosv
CVE-2025-61457P4MEDIUM≥ 0, < 9.7.02025-10-21
CVE-2025-61457 [MEDIUM] CWE-79 code16 Sharp vulnerable to Cross Site Scripting (XSS) code16 Sharp vulnerable to Cross Site Scripting (XSS) code16 Sharp v9.6.6 is vulnerable to Cross Site Scripting (XSS) src/Form/Fields/SharpFormUploadField.php.
ghsaosv
CVE-2026-53634P4MEDIUMCVSS 4.3v>= 9.0.0, < 9.22.32026-06-10
CVE-2026-53634 [MEDIUM] CWE-862 CVE-2026-53634: Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of the Quick Creation Command feature did not enforce any authorization check. An authenticated Sharp user without create permission on a given entity could bypass the authorization layer and either retr
ghsanvd
Code16 Sharp vulnerabilities | cvebase