A user with access to the backoffice can upload SVG files that include scripts. If the user can trick another user to load the media directly in a browser, the scripts can be executed.
Implement the server side file validation https://docs.umbraco.com/umbraco-cms/reference/security/serverside-file-validation
or
Serve all media from an different host (e.g cdn) that where umbraco is hosted
{
"severity": "LOW",
"github_reviewed_at": "2023-12-13T13:30:53Z",
"cwe_ids": [
"CWE-79"
],
"nvd_published_at": "2023-12-12T20:15:08Z",
"github_reviewed": true
}