cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forsafe-svg safe-svg

Direction: descending
Sep 24, 2026

Safe SVG # CVE-2023-28426

CVE, Research URL

-

Application

Safe SVG

Date
Mar 20, 2023
Research Description
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: GHSA-xrqq-wqh4-5hg2. Reason: Further investigation showed that this CVE was assigned in error. Notes: See https://github.com/darylldoyle/svg-sanitizer/issues/88 for a technical discussion.
Affected versions
max 2.1.0.
Status
vulnerable

Safe SVG # CVE-2026-94077

CVE, Research URL

CVE-2026-94077

Application

Safe SVG

Date
-
Research Description
Safe SVG [safe-svg] < 2.5.1 CVE-2026-94077
Affected versions
max 2.5.1.
Status
vulnerable
Jun 15, 2026

Safe SVG # 283b46cd2aaea9f407078879986fdfb01d2e8395

Application

Safe SVG

Date
Nov 05, 2019
Research Description
Safe SVG [safe-svg] < 1.9.5 WordPress Safe SVG plugin <= 1.9.4 - Denial of Service (DoS) attack vulnerability Denial of Service (DoS) attack vulnerability found by Nguyen Thanh Nguyen in WordPress Safe SVG plugin (versions <= 1.9.4).
Affected versions
max 1.9.5.
Status
vulnerable

Safe SVG # a09f3a03b68bd434ac92215debd2ba2010ee8182

Application

Safe SVG

Date
Mar 25, 2022
Research Description
Safe SVG [safe-svg] < 1.9.10 WordPress Safe SVG plugin <= 1.9.9 - SVG Sanitization Bypass vulnerability SVG Sanitization Bypass vulnerability discovered by David Hamann in WordPress Safe SVG plugin (versions <= 1.9.9).
Affected versions
max 1.9.10.
Status
vulnerable

Safe SVG # f9910881885d2526199e54e64208fc5bb9845398

Application

Safe SVG

Date
Nov 11, 2019
Research Description
Safe SVG [safe-svg] < 1.9.6 WordPress Safe SVG plugin <=1.9.5 - Cross-Site Scripting (XSS) vulnerability Cross-Site Scripting (XSS) vulnerability found by 0xd0ff9 in WordPress Safe SVG plugin (versions <=1.9.5).
Affected versions
max 1.9.6.
Status
vulnerable

Safe SVG # 98a126a3df672dc75eaf17109a29b3151cb0ec7c

Application

Safe SVG

Date
Nov 08, 2019
Research Description
Safe SVG [safe-svg] < 1.9.6 Safe SVG <= 1.9.5 - Cross-Site Scripting The Safe SVG plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Affected versions
max 1.9.6.
Status
vulnerable

Safe SVG # a23e3629-c6d7-478a-9c74-0f3d27430216

Application

Safe SVG

Date
-
Research Description
Safe SVG [safe-svg] < 1.9.6 Safe SVG &lt; 1.9.6 - XSS Protection Bypass By using entities in payload XSS will success to bypass the protection of the Safe SVG Plugin
Affected versions
max 1.9.6.
Status
vulnerable
Feb 17, 2025

Safe SVG # PSC-2024-64555

PSC, Research URL

PSC-2024-64555

Application

Safe SVG

Date
Aug 05, 2025
Research Description
Safe SVG is the most reliable WordPress plugin for securely allowing SVG file uploads while ensuring robust security measures. Unlike native WordPress behavior, which restricts SVG uploads due to potential security vulnerabilities, Safe SVG sanitizes and optimizes uploaded SVG files, protecting websites from XML-based threats and malicious code injection. With over 1 million downloads, Safe SVG is a trusted solution for safely handling scalable vector graphics within WordPress. The plugin has undergone extensive security testing and has been awarded the Plugin Security Certification (PSC) from CleanTalk, verifying its adherence to the highest security standards.
Affected versions
Min 2.5.1, max 2.5.1.
Status
SAFE & CERTIFIED
Nov 08, 2024

Safe SVG # CVE-2024-8378

CVE, Research URL

CVE-2024-8378

Application

Safe SVG

Date
Nov 07, 2024
Research Description
The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.
Affected versions
max 2.2.6.
Status
vulnerable
Jun 07, 2024

Safe SVG # CVE-2022-1091

CVE, Research URL

CVE-2022-1091

Application

Safe SVG

Date
Apr 18, 2022
Research Description
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks).
Affected versions
max 1.9.10.
Status
vulnerable

Safe SVG # CVE-2019-18854

CVE, Research URL

CVE-2019-18854

Application

Safe SVG

Date
Nov 11, 2019
Research Description
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.
Affected versions
max 1.9.5.
Status
vulnerable

Safe SVG # CVE-2019-18855

CVE, Research URL

CVE-2019-18855

Application

Safe SVG

Date
Nov 11, 2019
Research Description
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes.
Affected versions
max 1.9.5.
Status
vulnerable