Allow Svg Files Project maintains a focused plugin or extension component that handles SVG file uploads and rendering, with a durable exposure pattern centered on web-based input handling. The recurring weakness classes—cross-site scripting through improper neutralization during page generation and unrestricted dangerous-file uploads—reflect the intersection of permissive file-type handling and insufficient sanitization of user-supplied content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Allow Svg Files Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1939HIGH The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to upload PHP files even when they a | Jun 20, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-2299MEDIUM The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS | Jul 25, 2022 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Allow Svg Files Project.
Media articles that mention a CVE ID that affects a product developed by Allow Svg Files Project — matched by CVE ID, not by vendor name.