Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

ubuntu логотип

CVE-2026-33168

4 месяца назад

Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

EPSS: Низкий
redhat логотип

CVE-2026-33168

4 месяца назад

Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-33168

4 месяца назад

Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

EPSS: Низкий
debian логотип

CVE-2026-33168

4 месяца назад

Action View provides conventions and helpers for building web pages wi ...

EPSS: Низкий
github логотип

GHSA-v55j-83pf-r9cq

4 месяца назад

Rails has a possible XSS vulnerability in its Action View tag helpers

EPSS: Низкий
fstec логотип

BDU:2026-07241

5 месяцев назад

Уязвимость компонента ActionView программной платформы Ruby on Rails, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260506-73-0040

3 месяца назад

Уязвимость rubygem-actionview

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-33168

Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-33168

Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 5.4
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-33168

Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

1%
Низкий
4 месяца назад
debian логотип
CVE-2026-33168

Action View provides conventions and helpers for building web pages wi ...

1%
Низкий
4 месяца назад
github логотип
GHSA-v55j-83pf-r9cq

Rails has a possible XSS vulnerability in its Action View tag helpers

1%
Низкий
4 месяца назад
fstec логотип
BDU:2026-07241

Уязвимость компонента ActionView программной платформы Ruby on Rails, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.5
1%
Низкий
5 месяцев назад
redos логотип
ROS-20260506-73-0040

Уязвимость rubygem-actionview

CVSS3: 6.5
1%
Низкий
3 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.