Svg-sanitizer Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-55166

    svg-sanitizer By-Passing Attribute Sanitization

    Last Modified: Apr 15, 2026
    Published: Aug 12, 2025

    CVE-2022-23638

    Cross-site Scripting in svg-sanitizer

    Last Modified: Apr 23, 2025
    Published: Feb 14, 2022

    CVE-2019-10772

    It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the xlink namespace by the sanitizer.

    Last Modified: Nov 21, 2024
    Published: Dec 11, 2019

    CVE-2019-18857

    darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected whitespace such as in the javascript	:alert substring.

    Last Modified: Nov 21, 2024
    Published: Nov 11, 2019
    Items Per Page
    Svg-Sanitizer_Project Vulnerabilities & Security CVEs | CVE-DB