« Volver al listado

10up

10up Safe SVG: vulnerabilidades y CVE

10up Safe SVG tiene 6 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses2
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-94672Media (4.3)0.21%—30 sept 2026
Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.
CVE-2026-94077Media (6.5)0.18%—30 sept 2026
Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
CVE-2024-8378Media (4.8)0.31%—7 nov 2024
The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload…
CVE-2022-1091Media (6.1)1.2%—18 abr 2022
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform…
CVE-2019-18855Alta (7.5)2.6%—11 nov 2019
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes.
CVE-2019-18854Alta (7.5)2.6%—11 nov 2019
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System1
  2. T1059.007 JavaScript1
  3. T1189 Drive-by Compromise1
  4. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de 10up