PT-2026-95397 · Sveltycms · Sveltycms

·

CVE-2026-93505

·

Published

2026-09-18

·

Updated

2026-09-19

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions SveltyCMS version 0.0.6
Description A remote cross site scripting issue exists within the SVG Media Upload component, specifically affecting the src/utils/media/media-service.server.ts file. Cross site scripting is a technique where malicious scripts are injected into trusted websites.
Recommendations Apply patch 05b4f9efeb79e9d72a693232334d7529687f896f for version 0.0.6.

Exploit

Fix

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93505

Affected Products

Sveltycms