Description
A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The attack may be launched remotely.
Recommendation
Update the dbgate-web package to the latest compatible version. Followings are version details:
- Affected version(s): < 7.1.5
- Patched version(s): 7.1.5
References
Could your website be exposed too?
SmartScanner can check your website for DbGate has cross site scripting via the SVG Icon String Handler component and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization - CVE-2026-65841
- Open WebUI Has Stored Cross-Site Scripting in SVG Renderer - CVE-2026-45346
- Svelte SSR vulnerable to cross-site scripting via spread attributes - CVE-2026-42599
- NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability - CVE-2026-30048


