FLAT-PFB0G (CVE-2026-44587)
OS Command Injection In carrierwave
0.6
Low
Ecosystem: RubyGems
Package: carrierwave
FLAT-VIVIR (CVE-2024-29034)
Server side cross-site scripting In carrierwave
4.6
Medium
Ecosystem: RubyGems
Package: carrierwave
FLAT-8WF11 (CVE-2023-49090)
Reflected cross-site scripting (XSS) In carrierwave
4.6
Medium
Ecosystem: RubyGems
Package: carrierwave
FLAT-QVAY8 (CVE-2021-21305)
Lack of data validation In ruby-carrierwave
1.3
Low
Ecosystem: Debian
Package: ruby-carrierwave
FLAT-TJCBR (CVE-2021-21288)
Server-side request forgery (SSRF) In ruby-carrierwave
1.3
Low
Ecosystem: Debian
Package: ruby-carrierwave