VYPR
Moderate severityNVD Advisory· Published Feb 14, 2022· Updated Apr 23, 2025

Cross-site Scripting in svg-sanitizer

CVE-2022-23638

Description

svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the svg-sanitizer library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no workaround available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
enshrined/svg-sanitizePackagist
< 0.15.00.15.0

Affected products

2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.