Safe SVG [safe-svg] < 2.2.6
unknown
[en] The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.6
- Disclosed:
- Nov 7, 2024
CVE-2024-8378 on NVD →
Safe SVG <= 2.2.5 - Authenticated (Author+) Stored Cross-Site Scripting via SVG
medium
The Safe SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scri...
- CVSS:
- 5.4
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.6
- Disclosed:
- Oct 17, 2024
CVE-2024-8378 on NVD →
SVG Sanitizer library <= 0.15.4 - Cross-Site Scripting Bypass
high
The SVG Sanitizer library is vulnerable to XSS Bypass in versions up to, and including, 0.15.4. This may allow an attacker to successfully upload an SVG with persistent Cross-Site Scripting payloads in cases where a plugin is using this library to safely process SVG files.
- CVSS:
- 7.2
- Affected:
- up to 2.0.3
- Fixed in:
- 2.1.0
- Disclosed:
- Mar 23, 2023
CVE-2023-28426 on NVD →
Safe SVG [safe-svg] < 2.1.0
unknown
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.0
- Disclosed:
- Mar 23, 2023
CVE-2023-28426 on NVD →
Safe SVG [safe-svg] < 1.9.10
unknown
[en] The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use o...
- Affected:
- up to 1.9.10
- Fixed in:
- 1.9.10
- Disclosed:
- Apr 18, 2022
CVE-2022-1091 on NVD →
Safe SVG <= 1.9.9 - Content-Type Bypass
high
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of upl...
- CVSS:
- 7.7
- Affected:
- up to 1.9.10
- Fixed in:
- 1.9.10
- Disclosed:
- Mar 25, 2022
CVE-2022-1091 on NVD →
Safe SVG [safe-svg] < 1.9.10
unknown
SVG Sanitization Bypass vulnerability discovered by David Hamann in WordPress Safe SVG plugin (versions <= 1.9.9).
- Affected:
- up to 1.9.10
- Fixed in:
- 1.9.10
- Disclosed:
- Mar 25, 2022
Safe SVG [safe-svg] < 1.9.5
unknown
[en] A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5
- Disclosed:
- Nov 11, 2019
CVE-2019-18854 on NVD →
Safe SVG [safe-svg] < 1.9.5
unknown
[en] A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes.
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5
- Disclosed:
- Nov 11, 2019
CVE-2019-18855 on NVD →
Safe SVG [safe-svg] < 1.9.6
unknown
Cross-Site Scripting (XSS) vulnerability found by 0xd0ff9 in WordPress Safe SVG plugin (versions <=1.9.5).
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.6
- Disclosed:
- Nov 11, 2019
Safe SVG <= 1.9.5 - Cross-Site Scripting
medium
The Safe SVG plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 5.4
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.6
- Disclosed:
- Nov 8, 2019
Safe SVG [safe-svg] < 1.9.6
unknown
The Safe SVG plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.6
- Disclosed:
- Nov 8, 2019
Safe SVG <= 1.9.4 - Denial of Service
medium
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes.
- CVSS:
- 6.5
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.5
- Disclosed:
- Nov 5, 2019
CVE-2019-18855 on NVD →
Safe SVG <= 1.9.4 - Denial of Service
medium
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.
- CVSS:
- 6.5
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.5
- Disclosed:
- Nov 5, 2019
CVE-2019-18854 on NVD →
Safe SVG [safe-svg] < 1.9.5
unknown
Denial of Service (DoS) attack vulnerability found by Nguyen Thanh Nguyen in WordPress Safe SVG plugin (versions <= 1.9.4).
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5
- Disclosed:
- Nov 5, 2019
Safe SVG [safe-svg] < 1.9.6
unknown
By using entities in payload XSS will success to bypass the protection of the Safe SVG Plugin
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database