CVE-2017-9516: Craft CMS

Medium severity, CVSS 5.4. EPSS: 2.8% chance of exploitation in the next 30 days.

Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.

Affected products

  • Craft CMS Craft CMS: up to and including 2.6.2981

Published 2017-06-08. Last modified 2026-06-17.