Known Vulnerabilities for products from Geminabox Project
Listed below are 3 of the newest known vulnerabilities associated with the vendor "Geminabox Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2017-16792 json | Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbit... | Not Provided | 2017-11-13 | 2025-04-20 |
| CVE-2017-14683 json | geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. | 8.8 - HIGH | 2017-09-25 | 2019-10-17 |
| CVE-2017-14506 json | geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homepage v... | 5.4 - MEDIUM | 2017-09-25 | 2019-10-17 |
Known software with vulnerabilities from Geminabox Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Geminabox Project | Geminabox | 0.1.0 |