Known Vulnerabilities for products from Plataformatec
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Plataformatec".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-16676 json | Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-sup... | 9.8 - CRITICAL | 2019-09-30 | 2019-10-04 |
| CVE-2019-16109 json | An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank conf... | 5.3 - MEDIUM | 2019-09-08 | 2020-08-24 |
| CVE-2019-5421 json | Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devise::Mo... | 9.8 - CRITICAL | 2019-04-03 | 2020-10-16 |
| CVE-2013-0233 json | Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain da... | Not Provided | 2013-04-25 | 2026-04-29 |
Known software with vulnerabilities from Plataformatec
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Plataformatec | Devise | 0.7.5 |
| Application | Plataformatec | Simple Form | - |