Showing 15 vulnerabilities on this page for publify_core

Signals CISA KEV Ransomware Nuclei
RubyGems vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction

Publify is a self hosted Web publishing platform on Rails. Prior to version 10.0.1 of Publify, corresponding to versions prior to 10.0.2 of the `publify_core` rubygem, publisher on a `publify` application is able to perform a cross-site scripting (XSS) attack on an administrator using the redirect functionality. The exploitation of this XSS vulnerability requires the administrator to click a malicious link. An attack could attempt to hide their payload by using HTML, or other encodings, as to no

CWE-79Mar 28, 2025
CVSS1.8v4.0EPSS0.248%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Weak Password Requirements in publify/publify

Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10.

CWE-521Jan 29, 2023
CVSS6.5v3.1EPSS0.7%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Input Validation in publify/publify

Improper Input Validation in GitHub repository publify/publify prior to 9.2.10.

CWE-20Jan 14, 2023
CVSS9.8v3.1EPSS0.909%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Insecure Storage of Sensitive Information in publify/publify

Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10.

CWE-922Jan 14, 2023
CVSS6.5v3.1EPSS0.562%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Integer Overflow or Wraparound in publify/publify

Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.

CWE-190Jan 14, 2023
CVSS9.8v3.1EPSS30.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Unrestricted Upload of File with Dangerous Type in publify/publify

Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.

CWE-434CWE-79May 23, 2022
CVSS5.4v3.1EPSS0.753%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Authorization Bypass Through User-Controlled Key in publify/publify

Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.

CVSS4.3v3.1EPSS0.827%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Leaking password protected articles content due to improper access control in publify/publify

Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users.

CWE-284CWE-863May 16, 2022
CVSS4.9v3.1EPSS1.23%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Code Injection in publify/publify

Code Injection in GitHub repository publify/publify prior to 9.2.8.

CWE-94May 16, 2022
CVSS6.5v3.1EPSS0.898%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Access Control in publify/publify

Improper Access Control in GitHub repository publify/publify prior to 9.2.8.

CWE-284CWE-863May 16, 2022
CVSS6.5v3.1EPSS0.828%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Business Logic Errors in publify/publify

Business Logic Errors in GitHub repository publify/publify prior to 9.2.7.

CWE-840CWE-841Feb 8, 2022
CVSS7.5v3.1EPSS1.57%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Publify - Stored Cross-Site Scripting (XSS) due to Unrestricted File Upload

In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file.

CWE-79Nov 10, 2021
CVSS5.4v3.1EPSS0.578%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Publify - Stored Cross-Site Scripting (XSS) in Editor

In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article.

CWE-79Nov 10, 2021
CVSS5.4v3.1EPSS0.578%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Publify - Improper Authorization Leads to Guest Signup Restriction Bypass

In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.

CVSS6.5v3.1EPSS0.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Publify vulnerable to DoS attack

Publify before 8.0.1 is vulnerable to a Denial of Service attack

CWE-400Jan 9, 2020
CVSS7.5v3.1EPSS1.08%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX