CVE-2026-94545Medium· 5.3▾ TwilightPoC availableSatori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.2 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
4 GitHub repos (last check)
Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgrading. Applications that cannot immediately upgrade should not render attacker-controlled content with Satori.
satori >= 0.0.27, < 0.33.5next >= 16.2.0, < 16.3.6Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-24682Medium· 6.1An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021
CVE-2026-25940High· 8.1jsPDF is a library to generate PDFs in JavaScript
CVE-2026-82409High· 8.4Klever-Go is the Go implementation of the Klever blockchain protocol
CVE-2026-58504Medium· 6.1draw.io is a configurable diagramming and whiteboarding application
CVE-2026-54506High· 7.6Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores
CVE-2026-13407Medium· 5.4The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated a…