Thoughtbot
2 CVEs tracked since 2013. Since Nov 2013, none of them reached CISA KEV.
Thoughtbot CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2013-11 | 1 | 0 |
| 2013-12 | null or fewer | |
| 2014-01 | null or fewer | |
| 2014-02 | null or fewer | |
| 2014-03 | null or fewer | |
| 2014-04 | null or fewer | |
| 2014-05 | null or fewer | |
| 2014-06 | null or fewer | |
| 2014-07 | null or fewer | |
| 2014-08 | null or fewer | |
| 2014-09 | null or fewer | |
| 2014-10 | null or fewer | |
| 2014-11 | null or fewer | |
| 2014-12 | null or fewer | |
| 2015-01 | null or fewer | |
| 2015-02 | null or fewer | |
| 2015-03 | null or fewer | |
| 2015-04 | null or fewer | |
| 2015-05 | null or fewer | |
| 2015-06 | null or fewer | |
| 2015-07 | 1 | 0 |
Products
The products that kept showing up in Thoughtbot's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 6 most recently published vulnerabilities affecting Thoughtbot.
- CVE-2016-3098Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code.5.4
- CVE-2021-23435Open Redirect7.6
- CVE-2020-5257Sort order SQL injection in Administrate7.7
- CVE-2017-0889Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about inte...9.8
- CVE-2015-2963The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-si...4.3
- CVE-2013-4457The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, related to recursive variable interpolation.6.8
The record
- Peak rank
- #109 in Jul 2015
- Busiest month shown
- Nov 2013, 1 CVEs
- Months with a KEV entry
- 0 since Nov 2013
- Monthly snapshots
- 2 since 2013