Vulnerabilities and security researches forsafe-svg safe-svg
Direction: descendingSep 24, 2026
Safe SVG # CVE-2023-28426
- CVE, Research URL
-
-
- Home page URL
- Application
- Date
- Mar 20, 2023
- Research Description
- Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: GHSA-xrqq-wqh4-5hg2. Reason: Further investigation showed that this CVE was assigned in error. Notes: See https://github.com/darylldoyle/svg-sanitizer/issues/88 for a technical discussion.
- Affected versions
-
max 2.1.0.
- Status
-
vulnerable
Safe SVG # CVE-2026-94077
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Safe SVG [safe-svg] < 2.5.1 CVE-2026-94077
- Affected versions
-
max 2.5.1.
- Status
-
vulnerable
Jun 15, 2026
Safe SVG # 283b46cd2aaea9f407078879986fdfb01d2e8395
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 05, 2019
- Research Description
- Safe SVG [safe-svg] < 1.9.5 WordPress Safe SVG plugin <= 1.9.4 - Denial of Service (DoS) attack vulnerability Denial of Service (DoS) attack vulnerability found by Nguyen Thanh Nguyen in WordPress Safe SVG plugin (versions <= 1.9.4).
- Affected versions
-
max 1.9.5.
- Status
-
vulnerable
Safe SVG # a09f3a03b68bd434ac92215debd2ba2010ee8182
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 25, 2022
- Research Description
- Safe SVG [safe-svg] < 1.9.10 WordPress Safe SVG plugin <= 1.9.9 - SVG Sanitization Bypass vulnerability SVG Sanitization Bypass vulnerability discovered by David Hamann in WordPress Safe SVG plugin (versions <= 1.9.9).
- Affected versions
-
max 1.9.10.
- Status
-
vulnerable
Safe SVG # f9910881885d2526199e54e64208fc5bb9845398
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 11, 2019
- Research Description
- Safe SVG [safe-svg] < 1.9.6 WordPress Safe SVG plugin <=1.9.5 - Cross-Site Scripting (XSS) vulnerability Cross-Site Scripting (XSS) vulnerability found by 0xd0ff9 in WordPress Safe SVG plugin (versions <=1.9.5).
- Affected versions
-
max 1.9.6.
- Status
-
vulnerable
Safe SVG # 98a126a3df672dc75eaf17109a29b3151cb0ec7c
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 08, 2019
- Research Description
- Safe SVG [safe-svg] < 1.9.6 Safe SVG <= 1.9.5 - Cross-Site Scripting The Safe SVG plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected versions
-
max 1.9.6.
- Status
-
vulnerable
Safe SVG # a23e3629-c6d7-478a-9c74-0f3d27430216
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Safe SVG [safe-svg] < 1.9.6 Safe SVG < 1.9.6 - XSS Protection Bypass By using entities in payload XSS will success to bypass the protection of the Safe SVG Plugin
- Affected versions
-
max 1.9.6.
- Status
-
vulnerable
Feb 17, 2025
Safe SVG # PSC-2024-64555
- PSC, Research URL
- Home page URL
- Application
- Date
- Aug 05, 2025
- Research Description
- Safe SVG is the most reliable WordPress plugin for securely allowing SVG file uploads while ensuring robust security measures. Unlike native WordPress behavior, which restricts SVG uploads due to potential security vulnerabilities, Safe SVG sanitizes and optimizes uploaded SVG files, protecting websites from XML-based threats and malicious code injection. With over 1 million downloads, Safe SVG is a trusted solution for safely handling scalable vector graphics within WordPress. The plugin has undergone extensive security testing and has been awarded the Plugin Security Certification (PSC) from CleanTalk, verifying its adherence to the highest security standards.
- Affected versions
-
Min 2.5.1, max 2.5.1.
- Status
-
SAFE & CERTIFIED
Nov 08, 2024
Safe SVG # CVE-2024-8378
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 07, 2024
- Research Description
- The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.
- Affected versions
-
max 2.2.6.
- Status
-
vulnerable
Jun 07, 2024
Safe SVG # CVE-2022-1091
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 18, 2022
- Research Description
- The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks).
- Affected versions
-
max 1.9.10.
- Status
-
vulnerable
Safe SVG # CVE-2019-18854
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 11, 2019
- Research Description
- A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.
- Affected versions
-
max 1.9.5.
- Status
-
vulnerable
Safe SVG # CVE-2019-18855
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 11, 2019
- Research Description
- A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes.
- Affected versions
-
max 1.9.5.
- Status
-
vulnerable