CVE-2026-93505
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
Summary
A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The patch is named 05b4f9efeb79e9d72a693232334d7529687f896f. Applying a patch is the recommended action to fix this issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | SveltyCMS | 0.0.6 | affected |
Weaknesses
- CWE-79: Cross Site Scripting
- CWE-94: Code Injection
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
Additional References
References
- https://vuldb.com/vuln/407422
- https://vuldb.com/vuln/407422/cti
- https://vuldb.com/cve/CVE-2026-93505
- https://vuldb.com/submit/942850
- https://github.com/SveltyCMS/SveltyCMS/commit/05b4f9efeb79e9d72a693232334d7529687f896f
- https://github.com/SveltyCMS/SveltyCMS/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.