A high-severity vulnerability affecting code16/sharp versions < 9.22.5, assigned CVE-2026-61823 with a CVSS score of 7.3, exists in code16 Sharp due to improper sanitization of the srcdoc attribute on iframe elements, allowing an attacker with permissions to edit an Editor field to inject malicious scripts and target other users viewing the content, potentially leading to session hijacking, account takeover and privilege escalation, and admin panel data theft. This flaw type is a stored cross-site scripting (XSS) vulnerability, which can be exploited through the attack vector of a user interface with restricted privileges. The business impact of this vulnerability includes unauthorized access to sensitive information, disruption of normal business operations, and potential financial losses due to compromised security.
We recommend you to update code16/Sharp to version 9.22.5.[/subscribe_to_unlock_form]
A high-severity vulnerability affecting code16/sharp versions < 9.22.5, assigned CVE-2026-61823 with a CVSS score of 7.3, exists in code16 Sharp due to improper sanitization of the srcdoc attribute on iframe elements, allowing an attacker with permissions to edit an Editor field to inject malicious scripts and target other users viewing the content, potentially leading to session hijacking, account takeover and privilege escalation, and admin panel data theft. This flaw type is a stored cross-site scripting (XSS) vulnerability, which can be exploited through the attack vector of a user interface with restricted privileges. The business impact of this vulnerability includes unauthorized access to sensitive information, disruption of normal business operations, and potential financial losses due to compromised security.
We recommend you to update code16/Sharp to version 9.22.5.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]