PT-2025-17590 · Unknown · Laravel Starter

Badtry

·

Published

2025-04-22

·

Updated

2025-04-23

·

CVE-2025-26159

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Laravel Starter version 11.11.0
Description The issue concerns Cross Site Scripting (XSS) in the tags feature. Users who can create or modify tags can inject malicious JavaScript code into the name field.
Recommendations For Laravel Starter version 11.11.0, update to a version that fixes the XSS issue in the tags feature, ensuring that user input in the name field is properly sanitized to prevent malicious JavaScript code injection.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-26159
GHSA-FPX3-H2PC-88VF

Affected Products

Laravel Starter