CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102279

LOWCVSS 3.1NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hovers over the tooltip. This issue is fixe

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-102279 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102279

LOWCVSS 3.1NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hovers over the tooltip. This issue is fixe

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]