Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin user can upload SVG which may load external data via XML DOM library. This can be used for insecure XML External Entity References. The problem has been patched in versions 2.6.9, 2.5.25, and 3.0.0-alpha3. As a workaround, one may patch the effect file `src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php` manually.
CVE ID: CVE-2025-47778
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.1
CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Vendor: sulu
Product: sulu
EPSS Score: 0.07% (probability of being exploited)
EPSS Percentile: 20.71% (scored less or equal to compared to others)
EPSS Date: 2025-06-12 (when was this score calculated)