Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Contribsys

First CVE: Apr 6, 2021Active for: 5 yearsTotal CVEs: 7

Contribsys maintains a focused portfolio of background-job and task-queue systems, notably Sidekiq and Faktory, that operate as critical infrastructure components in Ruby and polyglot application stacks. Vulnerabilities affecting this vendor skew toward serious outcomes, frequently acquire public exploit code, and reflect resource-handling and input-validation challenges inherent to message-queue and job-processing architectures—including cross-site scripting, denial-of-service through uncontrolled resource consumption, and insufficient data-authenticity verification. Defenders should prioritize patches for these systems, particularly where they process untrusted job payloads or are exposed to network boundaries; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Contribsys over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 6, 2021
5 years ago
Most Recent CVE
Mar 1, 2024
875 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-1892CRITICAL
Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
Apr 21, 20239.643NOYES
CVE-2021-30151MEDIUM
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
Apr 6, 20216.133NOYES
CVE-2022-23837HIGH
In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and make
Jan 21, 20227.527NONO
CVE-2023-37279HIGH
Faktory is a language-agnostic persistent background job server. Prior to version 1.8.0, the Faktory web dashboard can suffer from denial of service by a crafted malicious url quer
Sep 20, 20237.521NONO
CVE-2023-46951MEDIUM
Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payload to the uniquejobs function.
Mar 1, 20246.120NONO
CVE-2023-46950MEDIUM
Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL to the filter functions.
Mar 1, 20246.120NONO
CVE-2023-26141MEDIUM
Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vuln
Sep 14, 20234.918NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
57%
29%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (42.9%)
Unknown0 (0.0%)
Required4 (57.1%)
Privileges Required
Low0 (0.0%)
High1 (14.3%)
None6 (85.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
28.6% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Contribsys.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Contribsys — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Contribsys's Products

View all 4 CNAs →

Top CWEs