CVE-2025-62798: CODE16 Sharp

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vulnerability was discovered in code16/sharp when rendering content using the SharpShowTextField component. In affected versions, expressions wrapped in {{ & }} were evaluated by Vue. This allowed attackers to inject arbitrary JavaScript or HTML that executes in the browser when the field is displayed. The issue has been fixed in v9.11.1 .

Affected products

  • CODE16 Sharp: before 9.11.1 (fixed in 9.11.1)

Published 2025-10-28. Last modified 2026-10-08.