Rubygeocoder maintains the Geocoder library, a Ruby gem that provides geolocation and geocoding functionality for web applications, and has disclosed vulnerabilities centered on SQL injection flaws in query construction. The exposure reflects risks endemic to database-backed geocoding where user input flows into spatial queries without sufficient parameterization, a structural concern for defenders integrating this library into location-aware applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rubygeocoder over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7981CRITICAL sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data. | Jan 25, 2020 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rubygeocoder.
Media articles that mention a CVE ID that affects a product developed by Rubygeocoder — matched by CVE ID, not by vendor name.