RubyGems Package Vulnerabilities
Vulnerabilities associated with publify_core.
Packages
Clear package- actionpack63 vulnerabilities
- nokogiri59 vulnerabilities
- rack50 vulnerabilities
- rubygems-update25 vulnerabilities
- activerecord23 vulnerabilities
- puppet23 vulnerabilities
- activesupport17 vulnerabilities
- camaleon_cms15 vulnerabilities
- publify_core15 vulnerabilities
- rails-html-sanitizer15 vulnerabilities
- passenger14 vulnerabilities
- puma14 vulnerabilities
- actionview13 vulnerabilities
- decidim13 vulnerabilities
- fat_free_crm12 vulnerabilities
- activestorage11 vulnerabilities
- loofah11 vulnerabilities
- oj11 vulnerabilities
- rails11 vulnerabilities
- net-imap10 vulnerabilities
- ruby-saml10 vulnerabilities
- decidim-core9 vulnerabilities
- jquery-rails9 vulnerabilities
- openc39 vulnerabilities
- avo8 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User InteractionPublify is a self hosted Web publishing platform on Rails. Prior to version 10.0.1 of Publify, corresponding to versions prior to 10.0.2 of the `publify_core` rubygem, publisher on a `publify` application is able to perform a cross-site scripting (XSS) attack on an administrator using the redirect functionality. The exploitation of this XSS vulnerability requires the administrator to click a malicious link. An attack could attempt to hide their payload by using HTML, or other encodings, as to no… CWE-79Mar 28, 2025 | CVSS1.8v4.0 | EPSS0.248% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-0569MEDIUM | Weak Password Requirements in publify/publifyWeak Password Requirements in GitHub repository publify/publify prior to 9.2.10. CWE-521Jan 29, 2023 | CVSS6.5v3.1 | EPSS0.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-0299CRITICAL | Improper Input Validation in publify/publifyImproper Input Validation in GitHub repository publify/publify prior to 9.2.10. CWE-20Jan 14, 2023 | CVSS9.8v3.1 | EPSS0.909% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-2815MEDIUM | Insecure Storage of Sensitive Information in publify/publifyInsecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. CWE-922Jan 14, 2023 | CVSS6.5v3.1 | EPSS0.562% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1812CRITICAL | Integer Overflow or Wraparound in publify/publifyInteger Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10. CWE-190Jan 14, 2023 | CVSS9.8v3.1 | EPSS30.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1811MEDIUM | Unrestricted Upload of File with Dangerous Type in publify/publifyUnrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9. | CVSS5.4v3.1 | EPSS0.753% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1810MEDIUM | Authorization Bypass Through User-Controlled Key in publify/publifyAuthorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9. | CVSS4.3v3.1 | EPSS0.827% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1553MEDIUM | Leaking password protected articles content due to improper access control in publify/publifyLeaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. | CVSS4.9v3.1 | EPSS1.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0578MEDIUM | Code Injection in publify/publifyCode Injection in GitHub repository publify/publify prior to 9.2.8. CWE-94May 16, 2022 | CVSS6.5v3.1 | EPSS0.898% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0574MEDIUM | Improper Access Control in publify/publifyImproper Access Control in GitHub repository publify/publify prior to 9.2.8. | CVSS6.5v3.1 | EPSS0.828% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0524HIGH | Business Logic Errors in publify/publifyBusiness Logic Errors in GitHub repository publify/publify prior to 9.2.7. | CVSS7.5v3.1 | EPSS1.57% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25975MEDIUM | Publify - Stored Cross-Site Scripting (XSS) due to Unrestricted File UploadIn publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. CWE-79Nov 10, 2021 | CVSS5.4v3.1 | EPSS0.578% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25974MEDIUM | Publify - Stored Cross-Site Scripting (XSS) in EditorIn Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. CWE-79Nov 10, 2021 | CVSS5.4v3.1 | EPSS0.578% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25973MEDIUM | Publify - Improper Authorization Leads to Guest Signup Restriction BypassIn Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only. | CVSS6.5v3.1 | EPSS0.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2014-3211HIGH | Publify vulnerable to DoS attackPublify before 8.0.1 is vulnerable to a Denial of Service attack CWE-400Jan 9, 2020 | CVSS7.5v3.1 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |