Benbodhi

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-48973

    WordPress SVG Support plugin <= 2.5.14 - Broken Access Control vulnerability

    Last Modified: May 28, 2026
    Published: May 27, 2026

    CVE-2024-10222

    SVG Support <= 2.5.10 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

    Last Modified: Apr 08, 2026
    Published: Feb 21, 2025

    CVE-2023-6708

    SVG Support <= 2.5.7 - Authenticated (Author+) Cross-Site Scripting via SVG

    Last Modified: Apr 15, 2026
    Published: Jul 18, 2024

    CVE-2022-4022

    The SVG Support plugin for WordPress defaults to insecure settings in version 2.5 and 2.5.1. SVG files containing malicious javascript are not sanitized. While version 2.5 adds the ability to sanitize image as they are uploaded, the plugin defaults to disable sanitization and does not restrict SVG upload to only administrators. This allows authenticated attackers, with author-level privileges and higher, to upload malicious SVG files that can be embedded in posts and pages by higher privileged users. Additionally, the embedded JavaScript is also triggered on visiting the image URL, which allows an attacker to execute malicious code in browsers visiting that URL.

    Last Modified: Feb 07, 2025
    Published: Nov 16, 2022

    CVE-2022-1755

    SVG Support < 2.5 - Author+ Stored Cross-Site Scripting

    Last Modified: May 21, 2025
    Published: Sep 26, 2022
    Items Per Page
    Benbodhi Vulnerabilities & Security CVEs | CVE-DB