Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Thoughtbot

First CVE: Nov 2, 2013Active for: 13 yearsTotal CVEs: 6

Thoughtbot maintains a focused portfolio of Ruby on Rails libraries and development tools—including administrate, paperclip, clearance, and cocaine—that serve as widely adopted components in web application stacks. Vulnerabilities affecting this vendor skew toward serious outcomes and recur through web-tier input-handling weakness classes including cross-site request forgery, cross-site scripting, SQL injection, and OS command injection, reflecting the injection-surface risks inherent to middleware and ORM components. Defenders should inventory downstream applications that depend on these libraries, as patching decisions often propagate across multiple services; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Thoughtbot over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 2, 2013
12 years ago
Most Recent CVE
Aug 5, 2022
1,449 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-0889CRITICAL
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access infor
Nov 13, 20179.831NONO
CVE-2020-5257HIGH
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard, the direction parameter was not validated before being interpolated into the SQL query.
Mar 13, 20208.125NONO
CVE-2021-23435MEDIUM
This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to cont
Sep 12, 20216.121NONO
CVE-2016-3098MEDIUM
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code.
Aug 5, 20225.420NONO
CVE-2013-4457MEDIUM
The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, related to recursive variable interpolation.
Nov 2, 20136.818NONO
CVE-2015-2963MEDIUM
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and
Jul 10, 20154.314NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
67%
17%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (66.7%)
Unknown2 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (66.7%)
High0 (0.0%)
Unknown2 (33.3%)
User Interaction
None2 (33.3%)
Unknown2 (33.3%)
Required2 (33.3%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None3 (50.0%)
Unknown2 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Thoughtbot.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Thoughtbot — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Thoughtbot's Products

View all 5 CNAs →

Top CWEs