svg-sanitizer vulnerabilities
CVEs whose affected-version data names the svg-sanitizer package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-107380Medium· 5.4savg-sanitizer is a PHP SVG/XML sanitizer
savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration.…
▾ Sunlitdarylldoyle · svg-sanitizervia NVD
CVE-2026-107379Medium· 6.5savg-sanitizer is a PHP SVG/XML sanitizer
savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer allows a crafted SVG DTD with a #FIXED attribute default to make cleanAttributesOnWhitelist() perform a double DOMElement::removeAttribute() call on the same attrib…
▾ Sunlitdarylldoyle · svg-sanitizervia NVD