← back
CVE-2018-16468CWE-79

CVE-2018-16468

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.9%
exploitation probability
0.9%top 41% of all CVEs
observed exploitation
nono source reports it
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
Affected products
n/a · Loofah (Ruby Gem)