Medium severity6.1NVD Advisory· Published Feb 16, 2016· Updated May 6, 2026
CVE-2015-7580
CVE-2015-7580
Description
Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
rails-html-sanitizerRubyGems | < 1.0.3 | 1.0.3 |
Affected products
1Patches
163903b0eaa6dVulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
10- github.com/advisories/GHSA-ghqm-pgxj-37gqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-7580ghsaADVISORY
- lists.opensuse.org/opensuse-security-announce/2016-02/msg00014.htmlnvdWEB
- lists.opensuse.org/opensuse-security-announce/2016-02/msg00024.htmlnvdWEB
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.htmlnvdWEB
- www.openwall.com/lists/oss-security/2016/01/25/15nvdWEB
- github.com/rails/rails-html-sanitizer/commit/63903b0eaa6d2a4e1c91bc86008256c4c8335e78nvdWEB
- groups.google.com/forum/message/rawnvdWEB
- web.archive.org/web/20160128075017/http://www.securitytracker.com/id/1034816ghsaWEB
- www.securitytracker.com/id/1034816nvd
News mentions
0No linked articles in our index yet.