Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12260 | Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field. |
Github GHSA |
GHSA-fpx3-h2pc-88vf | Laravel Starter Cross Site Scripting (XSS) |
Tue, 22 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 22 Apr 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-22T20:43:07.620Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-26159
Updated: 2025-04-22T20:43:02.179Z
Status : Deferred
Published: 2025-04-22T20:15:28.130
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-26159
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA