CVE · High

CVE-2019-18854 — Safe SVG [safe-svg] < 1.9.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-18854 Safe SVG [safe-svg] < 1.9.5 Uncontrolled Recursion High 7.5 < 1.9.5 1.9.5 2019-11-05

CVE-2019-18854

A denial of service flaw was identified in Safe SVG plugin versions up to 1.9.4 that allows an attacker to trigger unbounded recursive processing when the plugin encounters SVG `<use>` elements with `xlink:href` attributes referencing internal identifiers. This recursive behavior can exhaust server resources and crash the application. The vulnerability was patched in version 1.9.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.