cleantalk
Vulnerabilities and Security Researches

Safe SVG, 98a126a3df672dc75eaf17109a29b3151cb0ec7c

Application

Safe SVG

Published on
Nov 08, 2019
Research Description
Safe SVG [safe-svg] < 1.9.6 Safe SVG <= 1.9.5 - Cross-Site Scripting The Safe SVG plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Affected versions
max 1.9.6.
Status
vulnerable