Avohq maintains a focused product line centered on the Avo data governance and lineage platform, with its vulnerability footprint reflecting input-handling and code-reflection issues common to web-facing data-catalog applications, such as cross-site scripting, improper input validation, and unsafe reflection of user-controlled input. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Avohq over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34102HIGH Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to operate on when updating a record with user input, and does not | Jun 5, 2023 | 8.8 | 27 | NO | NO |
CVE-2026-33209MEDIUM Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.30.3, a reflected cross-site scripting (XSS) vulnerability exists in the return_to query parame | Mar 20, 2026 | 6.1 | 22 | NO | NO |
CVE-2024-22411MEDIUM Avo is a framework to create admin panels for Ruby on Rails apps. In Avo 3 pre12, any HTML inside text that is passed to `error` or `succeed` in an `Avo::BaseAction` subclass will | Jan 16, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-22191MEDIUM Avo is a framework to create admin panels for Ruby on Rails apps. A stored cross-site scripting (XSS) vulnerability was found in the key_value field of Avo v3.2.3 and v2.46.0. This | Jan 16, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-34103MEDIUM Avo is an open source ruby on rails admin panel creation framework. In affected versions some avo fields are vulnerable to Cross Site Scripting (XSS) when rendering html based cont | Jun 5, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Avohq.
Media articles that mention a CVE ID that affects a product developed by Avohq — matched by CVE ID, not by vendor name.