Medium 4.7
2025-09-22< 7.9.8
Admin and Site Enhancements <= 7.9.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG
Minimum safe version
8.4.1
Update to 8.4.1 or later to address 10 fixable vulnerabilities
Admin and Site Enhancements <= 7.9.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG
CVE-2026-32423
Admin and Site Enhancements (ASE) <= 8.0.8 - Missing Authorization
CVE-2024-13688
CVE-2024-13685
CVE-2024-43333
Admin and Site Enhancements (ASE) <= 7.6.2.1 - Authenticated (Subscriber+) Privilege Escalation
CVE-2025-24649
CVE-2024-10790
CVE-2023-46630