CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian Loofah ProjectRubyonrails3Debian Linux LoofahRails Html SanitizersNov 3, 2025 Dec 14, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scripting via data URIs when used in combination with Loofah >= 2.1.0. This...Show more |
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to s...Show more |
2Debian Loofah Project2Debian Linux LoofahNov 3, 2025 Dec 14, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type i...Show more |
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtr...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLoofah+1 moreNov 21, 2024 Oct 22, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. |
2Debian Loofah Project2Debian Linux LoofahNov 21, 2024 Oct 30, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. |
2Debian Loofah Project2Debian Linux LoofahNov 21, 2024 Mar 27, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment. |