Skip to main content

Vendor/product archive

rubyonrails / html_sanitizer CVEs

Beta · best-effort

4 CVEs tagged to rubyonrails / html_sanitizer0 Critical, 0 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2018-3741

Published Mar 30, 2018

There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output wh…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1