The Svg2png Project maintains a specialized image-conversion utility that translates SVG vector graphics to PNG raster format, a narrowly scoped tool with modest deployment relative to broader graphics and web infrastructure. Observed vulnerabilities center on cross-site scripting weaknesses arising from improper input neutralization during SVG processing and rendering, a recurrent pattern in tools that parse and transform untrusted markup. Current CVE counts, severity, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Svg2png Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11887MEDIUM svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document. | Apr 17, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Svg2png Project.
Media articles that mention a CVE ID that affects a product developed by Svg2png Project — matched by CVE ID, not by vendor name.