Package impact
Packagist / code16/sharp
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-44692 | high | — | 8.0 | 14d ago | Authenticated Sharp users can download unrelated Laravel Storage objects through the generic download endpoint | |||
| CVE-2026-33686 | unknown | — | — | 2mo ago | Sharp is Vulnerable to Path Traversal via Unsanitized Extension in FileUtil | |||
| CVE-2026-33687 | unknown | — | — | 2mo ago | Sharp has Unrestricted File Upload via Client-Controlled Validation Rules | |||
| CVE-2025-62798 | unknown | — | — | 7mo ago | Sharp user-provided input can be evaluated in a SharpShowTextField with Vue template syntax | |||
| CVE-2025-61457 | unknown | — | — | 7mo ago | code16 Sharp vulnerable to Cross Site Scripting (XSS) |