Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rubyonrails

First CVE: Aug 14, 2006Active for: 20 yearsTotal CVEs: 144
54.8
VTI Score
TOP TARGET

Ruby on Rails is a widely adopted web-application framework that underpins a substantial portion of the internet's public-facing applications, making its security posture relevant across an enormous downstream user base despite a narrow product count. Vulnerabilities affecting the framework and its core components such as ActionPack and HTML sanitizers skew toward moderate severity and cluster around input-handling and output-encoding weaknesses including cross-site scripting, SQL injection, and improper input validation—attack surfaces inherent to a web-facing request-processing architecture. The framework's vulnerabilities frequently acquire public proof-of-concept code, reflecting both the transparency of open-source development and the appeal of web-application frameworks to security researchers. Defenders deploying Rails applications should prioritize the framework's security releases and treat input-sanitization and parameterized-query practices as foundational controls; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
144
Total CVEs
More Total CVEs than 99% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 7% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
2.1%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Rubyonrails over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2006
19 years ago
Most Recent CVE
Mar 26, 2026
124 days ago

Products(14 total)

Top CVEs

Signals from CVEs in this vendor scope (144 CVEs).

144 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-5418HIGH
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrar
Mar 27, 20197.599YESYES
CVE-2016-0752HIGH
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote
Feb 16, 20167.597YESYES
CVE-2019-5420CRITICAL
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. Thi
Mar 27, 20199.890NOYES
CVE-2013-0156HIGH
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of st
Jan 13, 20137.589NOYES
CVE-2013-0333HIGH
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML pars
Jan 30, 20137.588NOYES
CVE-2016-2098HIGH
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's un
Apr 7, 20167.384NOYES
CVE-2014-0130HIGH
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x
May 7, 20147.583YESNO
CVE-2020-8163HIGH
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
Jul 2, 20208.882NOYES
CVE-2021-22881MEDIUM
The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "
Feb 11, 20216.178NOYES
CVE-2015-3224MEDIUM
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address,
Jul 26, 20154.369NOYES
View all 144 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products144 CVEs
65%
29%
Severity distribution among all CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network80 (55.6%)
Unknown64 (44.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low73 (50.7%)
High7 (4.9%)
Unknown64 (44.4%)
User Interaction
None48 (33.3%)
Unknown64 (44.4%)
Required32 (22.2%)
Privileges Required
Low4 (2.8%)
High1 (0.7%)
None75 (52.1%)
Unknown64 (44.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (144 CVEs).

CISA KEV
3 CVEs
2.1% of CVEs· 99th percentile
Metasploit
8 CVEs
5.6% of CVEs· 98th percentile
Nuclei
5 CVEs
3.5% of CVEs· 95th percentile
ExploitDB
11 CVEs
7.6% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rubyonrails.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rubyonrails — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rubyonrails's Products

View all 5 CNAs →

Top CWEs