Benbodhi
Benbodhi SVG Support: vulnerabilidades y CVE
Benbodhi SVG Support tiene 7 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-13340 | Media (6.1) | 0.25% | — | 3 ago 2026 | The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs… |
| CVE-2026-48973 | Media (4.3) | 0.25% | — | 27 may 2026 | Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SVG Support: from n/a through 2.5.14. |
| CVE-2024-10222 | Media (5.4) | 0.46% | — | 21 feb 2025 | The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. This makes… |
| CVE-2023-6708 | Media (5.4) | 0.34% | — | 18 jul 2024 | The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping, even… |
| CVE-2022-4022 | Media (5.4) | 0.45% | — | 16 nov 2022 | The SVG Support plugin for WordPress defaults to insecure settings in version 2.5 and 2.5.1. SVG files containing malicious javascript are not sanitized. While version 2.5 adds the ability to sanitize image as they are… |
| CVE-2022-1755 | Media (5.4) | 0.64% | — | 26 sept 2022 | The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks |
| CVE-2021-24686 | Media (4.8) | 0.65% | — | 1 feb 2022 | The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even… |