Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The patch is named 05b4f9efeb79e9d72a693232334d7529687f896f. Applying a patch is the recommended action to fix this issue. | |
| Title | SveltyCMS SVG Media Upload media-service.server.ts cross site scripting | |
| First Time appeared |
Sveltycms
Sveltycms sveltycms |
|
| Weaknesses | CWE-79 CWE-94 |
|
| CPEs | cpe:2.3:a:sveltycms:sveltycms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sveltycms
Sveltycms sveltycms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-18T15:43:38.878Z
Reserved: 2026-09-18T08:26:48.749Z
Link: CVE-2026-93505
Updated: 2026-09-18T15:43:25.297Z
Status : Received
Published: 2026-09-18T15:17:19.230
Modified: 2026-09-18T16:17:14.620
Link: CVE-2026-93505
No data.
OpenCVE Enrichment
No data.
