Convert Svg Core Project maintains a specialized SVG conversion library with a narrow product scope but embedded across a range of applications and workflows that depend on image format handling. The exposure signal, sparse as it is, reflects the parser and format-conversion role the library plays in downstream consumers. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Convert Svg Core Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25759CRITICAL The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload. | Jul 22, 2022 | 9.8 | 37 | NO | NO |
CVE-2022-24429HIGH The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file sys | Jun 10, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-23631HIGH This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of package convert-svg-to-jpeg. Using a specially crafted SVG file, | Jan 21, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Convert Svg Core Project.
Media articles that mention a CVE ID that affects a product developed by Convert Svg Core Project — matched by CVE ID, not by vendor name.