CVE-2024-53985
- EPSS 0.33%
- Published 02.12.2024 22:15:11
- Last modified 15.08.2025 19:41:49
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x ...
CVE-2024-53986
- EPSS 0.24%
- Published 02.12.2024 22:15:11
- Last modified 15.08.2025 18:54:58
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability wit...
CVE-2024-53987
- EPSS 0.24%
- Published 02.12.2024 22:15:11
- Last modified 15.08.2025 18:53:05
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability wit...
CVE-2024-53988
- EPSS 0.24%
- Published 02.12.2024 22:15:11
- Last modified 15.08.2025 18:51:56
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability wit...
CVE-2024-53989
- EPSS 0.24%
- Published 02.12.2024 21:15:11
- Last modified 15.08.2025 19:41:58
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability wit...
CVE-2022-23520
- EPSS 0.37%
- Published 14.12.2022 18:15:17
- Last modified 13.02.2025 17:15:38
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer due to an incomplete fix of CVE-2022-32209. R...
CVE-2022-23519
- EPSS 0.15%
- Published 14.12.2022 17:15:11
- Last modified 13.02.2025 17:15:37
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the applica...
CVE-2022-23517
- EPSS 0.22%
- Published 14.12.2022 17:15:10
- Last modified 21.11.2024 06:48:43
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to san...
CVE-2022-23518
- EPSS 0.23%
- Published 14.12.2022 17:15:10
- Last modified 21.11.2024 06:48:43
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scripting via data URIs when used in combination with Loofah >= 2.1.0. This issue is patched in version 1...
CVE-2022-32209
- EPSS 4.91%
- Published 24.06.2022 15:15:11
- Last modified 21.11.2024 07:05:55
# Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.This vulnerability has been assigned the CVE identifier CVE-2022-32209.Versions Affected: ALLNot affecte...