alchemy-cms CVE 脆弱性と CVE 一覧(2)

製品(CPE): — CVE 件数: 2

alchemy-cms 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to alchemy-cms, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 12 / 2 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-23885 Alchemy is an open source content management system engine written in Ruby on Rails. Prior to versions 7.4.12 and 8.0.3, the application uses the Ruby `eval()` function to dynamically execute a string provided by the `resource_handler.engine_name` attribute in `Alchemy::ResourcesHelper#resource_url_proxy`. The vulnerability exists in `app/helpers/alchemy/resources_helper.rb` at line 28. The code explicitly bypasses security linting with `# rubocop:disable Security/Eval`, indicating that the use [email protected] 6.4 0.05% 2026-01-19 2026-04-09
CVE-2018-18307 A Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field. NOTE: the vendor's position is that this is not a valid report: "The researcher used an authorized cookie to perform the request to a password-protected route. Without that session cookie, the request would have been rejected as unauthorized." [email protected] 6.1 0.34% 2018-10-16 2025-08-29
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence