Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
5.4
CVE-2024-5945
- EPSS 0.23%
- Veröffentlicht 21.06.2024 08:15:09
- Zuletzt bearbeitet 21.11.2024 09:48:37
The WP SVG Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘type’ parameter in all versions up to, and including, 4.2 due to insufficient input sanitization. This makes it possible for authenticated attackers, with Au...
5.4
CVE-2021-24386
- EPSS 0.18%
- Veröffentlicht 06.07.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:52:57
The WP SVG images WordPress plugin before 3.4 did not sanitise the SVG files uploaded, which could allow low privilege users such as author+ to upload a malicious SVG and then perform XSS attacks by inducing another user to access the file directly. ...
1