VYPR
Medium severity5.4NVD Advisory· Published Jun 8, 2017· Updated May 13, 2026

CVE-2017-9516

CVE-2017-9516

Description

Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
craftcms/cmsPackagist
< 2.6.29822.6.2982

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.