VendorsRuby on Railsrailsall versions
Vulnerabilities

Ruby on Rails Rails

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

122CVEs
CVE-2011-4319
Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with an "html" substring.
Published 2011-11-28 · Modified
4.3EPSS 0.016
CVE-2012-3463
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the prompt field to the select_tag helper.
Published 2012-08-10 · Modified
4.3EPSS 0.013
← Prev4 / 4