Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2022-23638
Disclosure Date: February 14, 2022 (last updated February 23, 2025)
svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no workaround available.
0
Attacker Value
Unknown
CVE-2020-11070
Disclosure Date: May 13, 2020 (last updated February 21, 2025)
The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invalid or incomplete SVG markup is not correctly processed and thus not sanitized at all. Albeit the markup is not valid it still is evaluated in browsers and leads to cross-site scripting. This is fixed in version 1.0.3.
0
Attacker Value
Unknown
CVE-2019-10772
Disclosure Date: December 11, 2019 (last updated November 27, 2024)
It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the xlink namespace by the sanitizer.
0
Attacker Value
Unknown
CVE-2019-18857
Disclosure Date: November 11, 2019 (last updated November 27, 2024)
darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected whitespace such as in the javascript	:alert substring.
0
Attacker Value
Unknown
CVE-2019-18856
Disclosure Date: November 11, 2019 (last updated November 27, 2024)
A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.
0