plugin

Safe Svg Vulnerabilities

16 known security issues reported for the Safe Svg WordPress plugin. Most recent disclosed Nov 7, 2024.

2 high 4 medium

Running Safe Svg on your site? Check whether your installed version is affected.

Scan your site free

Safe SVG [safe-svg] < 2.2.6

unknown

[en] The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.

Affected:
up to 2.2.6
Fixed in:
2.2.6
Disclosed:
Nov 7, 2024

CVE-2024-8378 on NVD →

Safe SVG <= 2.2.5 - Authenticated (Author+) Stored Cross-Site Scripting via SVG

medium

The Safe SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scri...

CVSS:
5.4
Affected:
up to 2.2.5
Fixed in:
2.2.6
Disclosed:
Oct 17, 2024

CVE-2024-8378 on NVD →

SVG Sanitizer library <= 0.15.4 - Cross-Site Scripting Bypass

high

The SVG Sanitizer library is vulnerable to XSS Bypass in versions up to, and including, 0.15.4. This may allow an attacker to successfully upload an SVG with persistent Cross-Site Scripting payloads in cases where a plugin is using this library to safely process SVG files.

CVSS:
7.2
Affected:
up to 2.0.3
Fixed in:
2.1.0
Disclosed:
Mar 23, 2023

CVE-2023-28426 on NVD →

Safe SVG [safe-svg] < 2.1.0

unknown
Affected:
up to 2.1.0
Fixed in:
2.1.0
Disclosed:
Mar 23, 2023

CVE-2023-28426 on NVD →

Safe SVG [safe-svg] < 1.9.10

unknown

[en] The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use o...

Affected:
up to 1.9.10
Fixed in:
1.9.10
Disclosed:
Apr 18, 2022

CVE-2022-1091 on NVD →

Safe SVG <= 1.9.9 - Content-Type Bypass

high

The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of upl...

CVSS:
7.7
Affected:
up to 1.9.10
Fixed in:
1.9.10
Disclosed:
Mar 25, 2022

CVE-2022-1091 on NVD →

Safe SVG [safe-svg] < 1.9.10

unknown

SVG Sanitization Bypass vulnerability discovered by David Hamann in WordPress Safe SVG plugin (versions <= 1.9.9).

Affected:
up to 1.9.10
Fixed in:
1.9.10
Disclosed:
Mar 25, 2022

Safe SVG [safe-svg] < 1.9.5

unknown

[en] A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.

Affected:
up to 1.9.5
Fixed in:
1.9.5
Disclosed:
Nov 11, 2019

CVE-2019-18854 on NVD →

Safe SVG [safe-svg] < 1.9.5

unknown

[en] A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes.

Affected:
up to 1.9.5
Fixed in:
1.9.5
Disclosed:
Nov 11, 2019

CVE-2019-18855 on NVD →

Safe SVG [safe-svg] < 1.9.6

unknown

Cross-Site Scripting (XSS) vulnerability found by 0xd0ff9 in WordPress Safe SVG plugin (versions <=1.9.5).

Affected:
up to 1.9.6
Fixed in:
1.9.6
Disclosed:
Nov 11, 2019

Safe SVG <= 1.9.5 - Cross-Site Scripting

medium

The Safe SVG plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
5.4
Affected:
up to 1.9.5
Fixed in:
1.9.6
Disclosed:
Nov 8, 2019

Safe SVG [safe-svg] < 1.9.6

unknown

The Safe SVG plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 1.9.6
Fixed in:
1.9.6
Disclosed:
Nov 8, 2019

Safe SVG <= 1.9.4 - Denial of Service

medium

A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes.

CVSS:
6.5
Affected:
up to 1.9.4
Fixed in:
1.9.5
Disclosed:
Nov 5, 2019

CVE-2019-18855 on NVD →

Safe SVG <= 1.9.4 - Denial of Service

medium

A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.

CVSS:
6.5
Affected:
up to 1.9.4
Fixed in:
1.9.5
Disclosed:
Nov 5, 2019

CVE-2019-18854 on NVD →

Safe SVG [safe-svg] < 1.9.5

unknown

Denial of Service (DoS) attack vulnerability found by Nguyen Thanh Nguyen in WordPress Safe SVG plugin (versions <= 1.9.4).

Affected:
up to 1.9.5
Fixed in:
1.9.5
Disclosed:
Nov 5, 2019

Safe SVG [safe-svg] < 1.9.6

unknown

By using entities in payload XSS will success to bypass the protection of the Safe SVG Plugin

Affected:
up to 1.9.6
Fixed in:
1.9.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database