{ "schema_version": "1.4.0", "id": "GHSA-qgp4-5qx6-548g", "modified": "2021-04-27T20:11:58Z", "published": "2021-04-30T17:30:06Z", "aliases": [ "CVE-2021-29460" ], "summary": "Cross-site scripting (XSS) from unsanitized uploaded SVG files in Kirby", "details": "### Impact\n\nAn editor with write access to the Kirby Panel can upload an SVG or XML file that contains harmful content like `