Haml is a templating language and markup processor used in Ruby web applications to generate HTML, with a narrowly scoped vulnerability footprint centered on the core haml product. The durable signal reflects input-handling risks inherent to template rendering, with observed disclosures clustered around cross-site scripting weaknesses arising from improper neutralization during web page generation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Haml over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1002201MEDIUM In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' characte | Oct 15, 2019 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Haml.
Media articles that mention a CVE ID that affects a product developed by Haml — matched by CVE ID, not by vendor name.