darylldoyle/safe-svg
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Activity
- Latest release
- 1w ago
- Total releases
- 26
- Cadence
- ~2 months
- Last 12 months
- 1
Reach
- Stars
- 338
Details
- License
- unknown
- First release
- Aug 21, 2019
| Version | Released | |
|---|---|---|
2.5.0
minor
| ||
2.4.0
minor
| ||
2.3.3
patch
| ||
2.3.2
patch
| ||
2.3.1
patch
| ||
2.3.0
minor
| ||
2.2.6
patch
| ||
2.2.5
patch
| ||
2.2.4
patch
| ||
2.2.3
patch
| ||
2.2.2
patch
| ||
2.2.1
patch
| ||
2.2.0
minor
| ||
2.1.1
patch
| ||
2.1.0
minor
| ||
2.0.3
patch
| ||
2.0.2
patch
| ||
2.0.1
patch
| ||
2.0.0
major
| ||
1.9.10
patch
| ||
1.9.9
patch
1 CVE
CVE-2022-1091
GHSA-5h7w-hmxc-99g5
Apr 19, 2022
Cross site scripting in safe-svg
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks). Affected versions
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
Fixed in
1.9.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.9.8
patch
1 CVE
CVE-2022-1091
GHSA-5h7w-hmxc-99g5
Apr 19, 2022
Cross site scripting in safe-svg
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks). Affected versions
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
Fixed in
1.9.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.9.7
patch
1 CVE
CVE-2022-1091
GHSA-5h7w-hmxc-99g5
Apr 19, 2022
Cross site scripting in safe-svg
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks). Affected versions
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
Fixed in
1.9.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.9.6
patch
1 CVE
CVE-2022-1091
GHSA-5h7w-hmxc-99g5
Apr 19, 2022
Cross site scripting in safe-svg
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks). Affected versions
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
Fixed in
1.9.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.9.5
patch
1 CVE
CVE-2022-1091
GHSA-5h7w-hmxc-99g5
Apr 19, 2022
Cross site scripting in safe-svg
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks). Affected versions
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
Fixed in
1.9.10
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.9.4
initial
1 CVE
CVE-2022-1091
GHSA-5h7w-hmxc-99g5
Apr 19, 2022
Cross site scripting in safe-svg
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks). Affected versions
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
Fixed in
1.9.10
References Updated Nov 08, 2023 · Source: OSV.dev |