CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Svg Sanitizer Project 1Svg Sanitizer Jun 17, 2026 Feb 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currentl...Show more |
1Svg Sanitizer Project 1Svg Sanitizer Jun 17, 2026 Dec 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the xlink namespace by the sanitizer. |
1Svg Sanitizer Project 1Svg Sanitizer Jun 17, 2026 Nov 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected whitespace such as in the javascript	:alert substring. |