Safe SVG

Safe SVG is a plugin for WordPress that allows for the upload of SVG files while sanitizing them to prevent vulnerabilities. It also enables users to preview uploaded SVGs in the media library. Future features include SVGO optimization and the ability to restrict uploads to certain users. The plugin was initially a proof of concept for a WordPress ticket.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Safe SVG 2.2.5

    Fixed

    The Safe SVG plugin for WordPress has a security issue that allows hackers to inject harmful code into website pages. This can happen when someone uploads an SVG file and it is not properly checked f...

    Read More
  • Input validation vulnerability in Safe SVG 2.0.3

    Fixed

    The SVG Sanitizer library

    Read More
  • Input validation vulnerability in Safe SVG 1.9.10

    Fixed

    The Safe SVG WordPress plugin was not properly protecting websites from malicious attacks before version 1.9.10. An attacker could bypass the built-in security measures by sending a false message with...

    Read More
  • Input validation vulnerability in Safe SVG 1.9.5

    Fixed

    The Safe SVG plugin for WordPress is not secure enough in versions up to 1.9.5, so it can be exploited by attackers. This means that attackers can add malicious web scripts into the plugin, and these...

    Read More
  • Denial of Service vulnerability in Safe SVG 1.9.4

    Fixed

    There is a security flaw in the Safe SVG plugin (also known as Safe SVG) for WordPress versions up to 1.9.4. This vulnerability allows for an infinite loop to be created when using a particular string...

    Read More
  • Denial of Service vulnerability in Safe SVG 1.9.4

    Fixed

    Read More