Vulnerabilities > Chartkick Project

DATE CVE VULNERABILITY TITLE RISK
2020-08-05 CVE-2020-16254 Injection vulnerability in Chartkick Project Chartkick
The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).
network
low complexity
chartkick-project CWE-74
6.1
2019-06-06 CVE-2019-12732 Cross-site Scripting vulnerability in Chartkick Project Chartkick
The Chartkick gem through 3.1.0 for Ruby allows XSS.
network
high complexity
chartkick-project CWE-79
4.7