PT-2026-98243 · Unknown · Code16/Sharp

CVE-2026-61825

·

Published

2026-09-24

·

Updated

2026-09-26

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions code16 Sharp versions prior to 9.22.5
Description A stored cross-site scripting issue exists in SharpEditorFormField. Attacker-controlled content using the data-html-content attribute can bypass HTML sanitization, allowing executable markup to be preserved and executed when another user views the stored content.
Recommendations Update to version 9.22.5. Sanitize all editor content before storing or rendering it. Disable SharpFormEditorField::RAW HTML functionality where it is not required.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61825
GHSA-VJ3Q-VP3G-J9C8

Affected Products

Code16/Sharp