SveltyCMS vulnerabilities
CVEs whose affected-version data names the SveltyCMS package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-93506Medium· 6.3A vulnerability was determined in SveltyCMS 0.0.6
A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Upload Endpoint. Executing a manipulation can lead to server-side request forgery.…
CVE-2026-93505Low· 3.5PoCA vulnerability was found in SveltyCMS 0.0.6
A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation results in cross site scripting. The a…
CVE-2026-93504Medium· 6.3A vulnerability has been found in SveltyCMS 0.0.6
A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such manipulation leads to improper access controls. It is p…