PT-2026-21843 · Typicms+1 · Typicms+1

Lukasz-Rybak

·

Published

2026-02-25

·

Updated

2026-02-25

·

CVE-2026-27621

CVSS v4.0

6.8

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TypiCMS versions prior to 16.1.7
Description TypiCMS is a content management system built on the Laravel framework. A stored cross-site scripting (XSS) issue exists in the file upload functionality. The application permits users with file upload privileges to upload SVG files, but it does not properly sanitize the file content despite MIME type validation. An attacker can upload a malicious SVG file containing JavaScript code. When another user views the file, the script executes in their browser, potentially compromising their session. The vulnerability is not mitigated by a 500 error that can occur if the SVG file lacks a viewBox attribute, as attackers can include a valid viewBox attribute in their payload.
Recommendations Update TypiCMS to version 16.1.7 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27621
GHSA-XFVG-8V67-J7WP

Affected Products

Laravel
Typicms