Vendor
high
advisory
Stored XSS Vulnerability in Code16 Sharp via iframe srcdoc Attribute
2 TTPs 1 CVEA stored XSS vulnerability in the Code16 Sharp rich text editor allows authenticated attackers to execute arbitrary JavaScript by exploiting browser-side HTML entity decoding within the iframe srcdoc attribute.
Sharp
web-application
xss
vulnerability
cve-2026-61825
2t
1c
high
advisory
code16/sharp Package Vulnerable to Path Traversal via Unsanitized File Extension
2 rules 1 TTPThe code16/sharp package is vulnerable to path traversal due to improper sanitization of file extensions, allowing authenticated attackers to manipulate file paths to write files outside the intended temporary directory or overwrite critical files.
sharp
path-traversal
web-application
php
code16/sharp
2r
1t