PT-2026-21843 · Typicms+1 · Typicms+1
Lukasz-Rybak
·
Published
2026-02-25
·
Updated
2026-02-25
·
CVE-2026-27621
CVSS v4.0
6.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TypiCMS versions prior to 16.1.7
Description
TypiCMS is a content management system built on the Laravel framework. A stored cross-site scripting (XSS) issue exists in the file upload functionality. The application permits users with file upload privileges to upload SVG files, but it does not properly sanitize the file content despite MIME type validation. An attacker can upload a malicious SVG file containing JavaScript code. When another user views the file, the script executes in their browser, potentially compromising their session. The vulnerability is not mitigated by a 500 error that can occur if the SVG file lacks a
viewBox attribute, as attackers can include a valid viewBox attribute in their payload.Recommendations
Update TypiCMS to version 16.1.7 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Laravel
Typicms