Description Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file. Remediation References CVE-2017-9516 Related Vulnerabilities WordPress 4.8.x Arbitrary File Deletion Vulnerability (4.8 - 4.8.6) PHP Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2011-0754) WordPress Plugin Ninja Forms Contact Form-The Drag and Drop Form Builder for WordPress Cross-Site Scripting (3.5.8.1) MySQL CVE-2017-3244 Vulnerability (CVE-2017-3244) WordPress Plugin MP3 Audio Player for Music, Radio & Podcast by Sonaar Multiple Cross-Site Scripting Vulnerabilities (2.4.1) Severity Medium Classification CVE-2017-9516 CWE-707 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities