Code16 / Sharp
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-61823 | code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute | HIGH | 7.3 | Sep 24, 2026 |
| CVE-2026-61825 | code16/sharp has a stored XSS via data-html-content Sanitizer Bypass | HIGH | 8.7 | Sep 24, 2026 |
| CVE-2026-44692 | Authenticated Sharp users can download unrelated Laravel Storage objects through the generic download endpoint | HIGH | 7.7 | Jun 10, 2026 |
| CVE-2026-53634 | Sharp: Missing Authorization Check in Quick Creation Command Endpoints | MEDIUM | 4.3 | Jun 10, 2026 |
| CVE-2026-33686 | Sharp is Vulnerable to Path Traversal via Unsanitized Extension in FileUtil | HIGH | 8.8 | Mar 26, 2026 |
| CVE-2026-33687 | Sharp has Unrestricted File Upload via Client-Controlled Validation Rules | HIGH | 8.8 | Mar 26, 2026 |
| CVE-2025-62798 | Sharp user-provided input can be evaluated in a SharpShowTextField with Vue template syntax | MEDIUM | 5.4 | Oct 28, 2025 |
Showing 1 to 7 of 7 CVEs