Activeadmin is a Ruby on Rails administrative framework used for building database-management interfaces, with a narrow but visible product footprint. The observed vulnerability pattern centers on improper neutralization of formula elements in CSV export functionality, a structural weakness in how the framework handles potentially malicious data in spreadsheet output. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Activeadmin over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-51763CRITICAL csv_builder.rb in ActiveAdmin (aka Active Admin) before 3.2.0 allows CSV injection. | Dec 24, 2023 | 9.8 | 24 | NO | NO |
CVE-2023-50448MEDIUM In ActiveAdmin (aka Active Admin) before 2.12.0, a concurrency issue allows a malicious actor to access potentially private data (that belongs to another user) by making CSV export | Dec 28, 2023 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Activeadmin.
Media articles that mention a CVE ID that affects a product developed by Activeadmin — matched by CVE ID, not by vendor name.