Vendors10upsafe_svgany version
Vulnerabilities

10up Safe SVG any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2019-18854
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.
Published 2019-11-11 · Modified
7.5EPSS 0.026
CVE-2019-18855
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes.
Published 2019-11-11 · Modified
7.5EPSS 0.026
CVE-2022-1091
Safe SVG < 1.9.10 - SVG Sanitisation Bypass
Published 2022-04-18 · Modified
6.1EPSS 0.012
CVE-2024-8378
Safe SVG < 2.2.6 - Author+ SVG Sanitisation Bypass
Published 2024-11-07 · Analyzed
4.8EPSS 0.003