CVE-2026-54498
- EPSS 0.31%
- Veröffentlicht 17.07.2026 20:46:52
- Zuletzt bearbeitet 29.07.2026 15:42:39
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the escaping behavior applied to n...
CVE-2026-54497
- EPSS 0.25%
- Veröffentlicht 17.07.2026 20:45:28
- Zuletzt bearbeitet 29.07.2026 15:43:39
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base instances retain render-scoped objects across calls to render_in; if the same component, co...
CVE-2026-44836
- EPSS 0.34%
- Veröffentlicht 26.05.2026 19:43:58
- Zuletzt bearbeitet 24.07.2026 11:10:00
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the preview route derives an example name from the URL and calls it with public_send. The code does not verify that...
CVE-2026-44837
- EPSS 0.41%
- Veröffentlicht 26.05.2026 19:40:47
- Zuletzt bearbeitet 24.07.2026 11:10:00
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the re...
CVE-2024-21636
- EPSS 0.5%
- Veröffentlicht 04.01.2024 20:15:25
- Zuletzt bearbeitet 21.11.2024 08:54:46
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. Versions prior to 3.9.0 and 2.83.0 have a cross-site scripting vulnerability that has the potential to impact anyone rendering a compone...