Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
pkg:RubyGems/
carrierwave
5 total CVEs
HIGH
1
MEDIUM
4
✅ Check your installed version
Check
All known vulnerabilities
HIGH
7.4
CVE-2021-21305
Code Injection vulnerability in CarrierWave::RMagick
from 0, < 1.3.2
MEDIUM
6.8
CVE-2024-29034
CarrierWave content-Type allowlist bypass vulnerability which possibly leads to XSS remained
>= 3.0.0, < 3.0.7
MEDIUM
6.8
CVE-2023-49090
CarrierWave Content-Type allowlist bypass vulnerability, possibly leading to XSS
>= 3.0.0, < 3.0.5
MEDIUM
4.7
CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters
>= 3.0.0.beta, < 3.1.3
MEDIUM
4.3
Server-side request forgery in CarrierWave
from 0, < 1.3.2
RubyGems/carrierwave — 5 CVEs · VulnScope
CVE-2026-44587
CVE-2021-21288