PT-2026-98242 · Unknown · Code16/Sharp

CVE-2026-61823

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions code16 Sharp versions prior to 9.22.5
Description A stored cross-site scripting issue exists in the rich-text editor because the HTML sanitizer allows the srcdoc attribute on iframe elements. While markup within srcdoc is HTML-encoded during sanitization, browsers decode these entities before interpreting the iframe document. This allows an authenticated user with permissions to edit an Editor field to store executable JavaScript that executes when another user views the content. This can lead to session hijacking, unauthorized actions, account takeover, privilege escalation, or disclosure of administrative data.
Recommendations Update to version 9.22.5. As a temporary workaround, manually sanitize all Editor field content and remove every iframe srcdoc attribute before storing or rendering it.

Exploit

Fix

LPE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61823
GHSA-QXG3-46RW-79J8

Affected Products

Code16/Sharp