VYPR

RubyGems package

alchemy_cms

pkg:gem/alchemy_cms

Vulnerabilities (2)

  • CVE-2026-23885MedJan 19, 2026
    affected < 7.4.12fixed 7.4.12

    Alchemy is an open source content management system engine written in Ruby on Rails. Prior to versions 7.4.12 and 8.0.3, the application uses the Ruby `eval()` function to dynamically execute a string provided by the `resource_handler.engine_name` attribute in `Alchemy::Resources

  • CVE-2018-18307Oct 16, 2018

    A Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field. NOTE: the vendor's position is that this is not a valid report: "The researcher used an authorized cookie to perform the request to a password-protected route. Witho