-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the SVG handling code in plupload.php. The pre-patch code:
This created a scenario where:
The patch added exception handling, validation checks, and only marks files as valid after confirmed successful sanitization, confirming this as the vulnerability source.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| microweber/microweber | composer | < 1.2.20 | 1.2.20 |
Ongoing coverage of React2Shell