VendorsCarrierWave Projectcarrierwaveall versions
Vulnerabilities

CarrierWave Project CarrierWave

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2021-21305
Code Injection vulnerability in CarrierWave
Published 2021-02-08 · Modified
8.8EPSS 0.127
CVE-2023-49090
CarrierWave has a content-type allowlist bypass vulnerability, possibly leading to XSS
Published 2023-11-29 · Modified
6.8EPSS 0.006
CVE-2024-29034
CarrierWave's Content-Type allowlist bypass vulnerability which possibly leads to XSS remained
Published 2024-03-24 · Analyzed
6.8EPSS 0.004
CVE-2026-44587
CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters
Published 2026-06-16 · Analyzed
6.1EPSS 0.003
CVE-2021-21288
Server-side request forgery in CarrierWave
Published 2021-02-08 · Modified
4.3EPSS 0.012