← Back

Svg Sanitizer Project

svg-sanitizer_project

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Svg Sanitizer
svg-sanitizer

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Svg Sanitizer Project
1Svg Sanitizer
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currentl...Show more
svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no workaround available.Show less
1Svg Sanitizer Project
1Svg Sanitizer
Jun 17, 2026
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the xlink namespace by the sanitizer.
1Svg Sanitizer Project
1Svg Sanitizer
Jun 17, 2026
Nov 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected whitespace such as in the javascript	:alert substring.