Stored XSS Vulnerability in LaraDashboard by LaraDashboard Ltd.
CVE-2026-90931
5.1MEDIUM
What is CVE-2026-90931?
The vulnerability in LaraDashboard allows authenticated users with the 'media.create' permission to upload harmful SVG files that are not properly sanitized. When these SVG files, containing dangerous script tags, are accessed, they execute embedded JavaScript within the context of the dashboard. This poses serious risks such as session hijacking and the potential for unauthorized administrative access, compromising user accounts and sensitive data.
Affected Version(s)
laradashboard 0.9.0 <= 1.4.2
