CVE-2026-49971

MEDIUM

Laravel-Mediable < 7.0.0 Stored XSS via SVG File Upload

Title source: cna
STIX 2.1

Description

Laravel-Mediable before 7.0.0 contains a stored cross-site scripting vulnerability that allows authenticated or anonymous users to execute arbitrary JavaScript by uploading unsanitized SVG files containing embedded scripts in onload event handlers, script tags, or foreignObject elements. Attackers can store persistent XSS payloads in uploaded SVG files that execute with full DOM access when victims open or preview the file, enabling session cookie theft, CSRF token capture, and account takeover.

Scores

CVSS v3 6.1
EPSS 0.0020
EPSS Percentile 10.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
plank/laravel-mediable < 7.0.0
Published Jul 13, 2026
Tracked Since Jul 14, 2026