Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

rubygems camaleon_cms Security Advisories

Browse all Security Advisories for rubygems camaleon_cms

Loading...
Moderate
GSA_kwCzR0hTQS1oaHhnLXJ2YzktODcyNs4ABAld
camaleon_cms affected by cross site scripting
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 6.1
Published: 29 days ago
Moderate
GSA_kwCzR0hTQS03NWoyLTlnbWMtbTg1Nc4AA_yE
Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 6.9
Published: about 2 months ago
Moderate
GSA_kwCzR0hTQS04Zng4LTNyZzItNzl4d84AA_uz
Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 6.9
Published: about 2 months ago
High
GSA_kwCzR0hTQS0zaHA4LTZqMjQtbTVnbc4AA_uy
Camaleon CMS vulnerable to remote code execution through code injection (GHSL-2024-185)
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 months ago
High
GSA_kwCzR0hTQS03eDR3LWNqOXItaDR2Oc4AA_rE
Camaleon CMS vulnerable to remote code execution through code injection (GHSL-2024-185)
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 9.2
Published: 2 months ago
Moderate
GSA_kwCzR0hTQS1yOWNyLXFtZnctcG1yY84AA_rD
Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 6.9
Published: 2 months ago
High
GSA_kwCzR0hTQS1jcDY1LTVtOXItdmMyY84AA_rC
Camaleon CMS vulnerable to arbitrary path traversal (GHSL-2024-183)
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 8.3
Published: 2 months ago
High
GSA_kwCzR0hTQS13bWpnLXZxaHYtcTVwNc4AA_ph
Camaleon CMS affected by arbitrary file write to RCE (GHSL-2024-182)
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 11.3
Published: 2 months ago
Critical
GSA_kwCzR0hTQS14NDg3LTg2Nm0tcDhocs4AAze4
Server-Side Template Injection in Camaleon CMS
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 12.5
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS14Nzh2LTRmdmotcmc5as4AArLe
Camaleon CMS Stored Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 7.8
Published: over 2 years ago
High
GSA_kwCzR0hTQS00Mzh4LTJwOXYtZzhoOc4AArCm
Camaleon CMS Insufficient Session Expiration vulnerability
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 11.3
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS1yMncyLWg2cjgtM3I1M84AAqXz
Camaleon CMS vulnerable to Uncaught Exception
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 5.5
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS12eDZwLXE0Z2oteDZ4eM4AAqWr
Camaleon CMS vulnerable to Server-Side Request Forgery
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 6.3
Published: over 2 years ago
Moderate
GSA_kwCzR0hTQS03Zjg0LTljcWYtZzRqOc3r0A
Camaleon CMS vulnerable to Stored Cross-site Scripting
Ecosystems: rubygems
Packages: camaleon_cms
Source: GitHub Advisory Database
Blast Radius: 7.8
Published: over 2 years ago
Statistics
Advisories: 20,668
Packages: 9,040
Repositories: 4
Ecosystems: 12
Filter by Package
actionpack 60 nokogiri 43 rubygems-update 25 rack 23 puppet 23 activerecord 21 camaleon_cms 14 activesupport 14 publify_core 14 passenger 13 puma 12 actionview 12 rails 11 decidim 11 fat_free_crm 10 jquery-rails 9 rails-html-sanitizer 9 twbs/bootstrap 9 bootstrap 9 org.webjars:bootstrap 9 bootstrap 9 bootstrap 9 jquery 8 org.webjars.npm:jquery 8 bootstrap-sass 8 jquery-ui 7 jquery-ui-rails 7 jQuery 7 bootstrap.sass 7 rexml 7 org.jruby:jruby-stdlib 7 org.webjars.npm:jquery-ui 7 jQuery.UI.Combined 7 katello 6 loofah 6 doorkeeper 6 ember-source 6 grpc 5 grpcio 5 spree 5 sidekiq 5 bootstrap-sass 5 bundler 5 spree_auth_devise 5 commonmarker 5 webrick 5 sinatra 5 ruby-saml 4 carrierwave 4 devise 4 rails_admin 4 mail 4 fluentd 4 avo 4 dragonfly 4 sanitize 4 activestorage 4 rack-cors 3 git 3 io.grpc:grpc-protobuf 3 google-protobuf 3 phlex 3 rdoc 3 chartkick 3 rubyzip 3 json-jwt 3 actiontext 3 omniauth 3 gollum 3 com.google.protobuf:protobuf-java 3 com.google.protobuf:protobuf-kotlin 3 yard 3 cgi 3 devise-two-factor 3 decidim-admin 3 geminabox 3 resque 3 rest-client 3 openssl 3 private_address_check 3 spina 3 activeadmin 3 decidim-core 3 openc3 3 openc3 3 faye 2 pdfkit 2 kaminari 2 administrate 2 sidekiq-unique-jobs 2 field_test 2 redcarpet 2 httparty 2 VladTheEnterprising 2 decidim-templates 2 twitter-bootstrap-rails 2 omniauth-facebook 2 mini_magick 2 ox 2 decidim-meetings 2 pageflow 2 secure_headers 2 radiant 2 facter 2 actionmailer 2 json 2 net-ldap 2 paperclip 2 uri 2 solidus_core 2 solidus_frontend 2 echor 2 qiita-markdown 2 cocoapods-downloader 2 safemode 2 yajl-ruby 2 omniauth-saml 2 pghero 2 logstash-core 2 user_agent_parser 2 git-fastclone 2 bson 2 view_component 2 com.google.protobuf:protobuf-javalite 2 sprockets 2 org.webjars.npm:bootstrap 2 mechanize 2 sup 2 @openc3/tool-common 2 com.google.protobuf:protobuf-kotlin-lite 2 kramdown 2 ruby-openid 2 mapbox-rails 2 pyarrow 2 red-arrow 2 i18n 2 maximebf/debugbar 2 mapbox.js 2 ruby-jss 1 rack-mini-profiler 1 activerecord-session_store 1 sha3 1 typo3/cms 1 hiera 1 mcollective-client 1 cap-strap 1 wicked 1 pysha3 1 narou 1 twitter-stream 1 sequenceserver 1 easymon 1 Bootstrap.Less 1 solidus_auth_devise 1 django 1 strong_password 1 restforce 1 matestack-ui-core 1 datagrid 1 iodine 1 activeresource 1 thin 1 sqlite3-ruby 1 faye-websocket 1 geocoder 1 dependabot-omnibus 1 dependabot-common 1 kelredd-pruview 1 typo3/cms-core 1 github.com/github/hub 1 apollo_upload_server 1 sisimai 1 exiftool_vendored 1 globalid 1 solidus_backend 1 uglify-js 1 uglifier 1 paratrooper-pingdom 1 rmagick 1 brbackup 1 kcapifony 1 personnummer 1 activejob 1 sfpagent 1 ldoce 1 omniauth-oauth2 1 gollum-lib 1 ciborg 1 lawn-login 1 keynote 1 chartkick 1 multi_xml 1 rails_multisite 1 geokit-rails 1 gitlab-grit 1 foreman_ansible 1 railties 1 fugit 1 Autolab 1 websocket-extensions 1