Sinatrateam develops Sinatra, a lightweight web application framework where the durable vulnerability signal centers on cross-site scripting weaknesses arising from improper input neutralization during web page generation. This reflects the framework's role as a foundation for developer-built web applications, where input-handling discipline falls to the application layer rather than the framework itself. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sinatrateam over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-37116MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sinatrateam Sinatra allows Stored XSS.This issue affects Sinatra: from | Jul 22, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sinatrateam.
Media articles that mention a CVE ID that affects a product developed by Sinatrateam — matched by CVE ID, not by vendor name.