VendorsRuby on Railsrailsany version
Vulnerabilities

Ruby on Rails Rails any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

56CVEs
CVE-2024-26143
Rails Possible XSS Vulnerability in Action Controller
Published 2024-02-27 · Analyzed
6.1EPSS 0.010
CVE-2023-22797
An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a carefully crafted URL resulting in an open redirect vulnerability.
Published 2023-02-09 · Modified
6.1EPSS 0.006
CVE-2024-32464
ActionText ContentAttachment can Contain Unsanitized HTML
Published 2024-06-04 · Modified
6.1EPSS 0.004
CVE-2026-33170
Rails Active Support has a possible XSS vulnerability in SafeBuffer#%
Published 2026-03-23 · Analyzed
6.1EPSS 0.004
CVE-2026-33167
Rails has a possible XSS vulnerability in its Action Pack debug exceptions
Published 2026-03-23 · Analyzed
6.1EPSS 0.003
CVE-2022-3704
Ruby on Rails _table.html.erb cross site scripting
Published 2022-10-26 · Modified
5.4EPSS 0.007
CVE-2016-0753
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
Published 2016-02-16 · Modified
5.3EPSS 0.072
CVE-2024-26144
Possible Sensitive Session Information Leak in Active Storage
Published 2024-02-27 · Analyzed
5.3EPSS 0.011
CVE-2026-33173
Rails Active Storage has possible content type bypass via metadata in direct uploads
Published 2026-03-23 · Analyzed
5.3EPSS 0.004
CVE-2013-6414
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.
Published 2013-12-07 · Modified
5.0EPSS 0.207
CVE-2012-6497
The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in secret_token.rb in an open-source product.
Published 2013-01-04 · Modified
5.0EPSS 0.027
CVE-2013-6415
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
Published 2013-12-07 · Modified
4.3EPSS 0.032
CVE-2013-4389
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.
Published 2013-10-17 · Modified
4.3EPSS 0.031
CVE-2013-4491
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
Published 2013-12-07 · Modified
4.3EPSS 0.022
CVE-2013-6416
Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.
Published 2013-12-07 · Modified
4.3EPSS 0.020
CVE-2020-8166
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
Published 2020-07-02 · Modified
4.3EPSS 0.017
← Prev2 / 2