Known Vulnerabilities for Rails by Rubyonrails
Listed below are 10 of the newest known vulnerabilities associated with "Rails" by "Rubyonrails".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73648 json | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML:... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-73330 json | CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-67990 json | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and P... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-66066 json | Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Ac... | Not Provided | 2026-07-30 | 2026-08-05 |
| CVE-2026-55518 json | Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach... | Not Provided | 2026-07-17 | 2026-07-20 |
| CVE-2026-54498 json | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 ... | Not Provided | 2026-07-17 | 2026-07-20 |
| CVE-2026-54497 json | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 ... | Not Provided | 2026-07-17 | 2026-07-20 |
| CVE-2026-52783 json | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module ... | Not Provided | 2026-06-26 | 2026-06-29 |
| CVE-2026-46386 json | OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker ima... | Not Provided | 2026-06-26 | 2026-06-29 |
| CVE-2026-45378 json | Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.r... | Not Provided | 2026-08-06 | 2026-08-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rubyonrails | Rails | 6.1.2.1 | |||
| Application | Rubyonrails | Rails | 6.1.2 | |||
| Application | Rubyonrails | Rails | 6.1.1 | |||
| Application | Rubyonrails | Rails | 6.1.0 | |||
| Application | Rubyonrails | Rails | 6.1.0 | |||
| Application | Rubyonrails | Rails | 6.1.0 | |||
| Application | Rubyonrails | Rails | 6.0.4 | |||
| Application | Rubyonrails | Rails | 6.0.3.5 | |||
| Application | Rubyonrails | Rails | 6.0.3.4 | |||
| Application | Rubyonrails | Rails | 6.0.3.3 | |||
| Application | Rubyonrails | Rails | 6.0.3.2 | |||
| Application | Rubyonrails | Rails | 6.0.3.1 | |||
| Application | Rubyonrails | Rails | 6.0.3 | |||
| Application | Rubyonrails | Rails | 6.0.3 | |||
| Application | Rubyonrails | Rails | 6.0.2.2 | |||
| Application | Rubyonrails | Rails | 6.0.2.1 | |||
| Application | Rubyonrails | Rails | 6.0.2 | |||
| Application | Rubyonrails | Rails | 6.0.2 | |||
| Application | Rubyonrails | Rails | 6.0.2 | |||
| Application | Rubyonrails | Rails | 6.0.1 |