{"id":"CVE-2024-47618","aliases":["GHSA-255w-87rh-rg44"],"url":"https://o3.security/vulnerability/CVE-2024-47618","summary":"Sulu vulnerable to XSS via uploaded SVG","details":"Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the “Media” section can upload an SVG file with a malicious payload. Once uploaded and accessed, the malicious javascript will be executed on the victims’ (other users including admins) browsers. This issue is fixed in 2.6.5.","published":"2024-10-03T14:18:02.129Z","modified":"2026-08-12T03:51:12.026340714Z","cvss":null,"epss":{"score":0.00362,"percentile":0.29506,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"sulu/sulu","fixedVersion":"2.5.21"},{"ecosystem":"Packagist","name":"sulu/sulu","fixedVersion":"2.6.5"}],"fix":{"url":"https://github.com/sulu/sulu/commit/ca72f75eebe41ea7726624d8aea7da6c425f1eb9","label":"sulu/sulu@ca72f75"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47618.json"},{"type":"ADVISORY","url":"https://github.com/sulu/sulu/security/advisories/GHSA-255w-87rh-rg44"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47618"},{"type":"FIX","url":"https://github.com/sulu/sulu/commit/ca72f75eebe41ea7726624d8aea7da6c425f1eb9"},{"type":"PACKAGE","url":"https://github.com/sulu/sulu"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.026340714Z"}}