Known vulnerabilities in YARD

Vendor: lsegal
Software: YARD
Software CPE: cpe:2.3:a:lsegal:yard:*:*:*:*:*:rubygems:*:*
Total vulnerabilities: 4
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting YARD YARD is affected by 4 known vulnerabilities: 3 medium, 1 low Critical High Medium Low

Vulnerabilities (4)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU132274 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-49342
CWE-22 Medium
No
No
0.9.44 25.05.2026 SB2026052536
SB2026070622
SB2026070623
#VU126592 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-41493
CWE-22 Medium
No
No
0.9.42 20.04.2026 SB20260420112
SB2026061942
SB2026061943
and 4 more
#VU87783 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-27285
CWE-79 Low
No
No
0.9.36 25.03.2024 SB2024032538
SB2024032539
SB2024032545
and 1 more
#VU126591 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-1020001
CWE-22 Medium
No
No
0.9.20 28.06.2019 SB2019062822
SB2021073112