Skip to content
Noroxi

yardoc records

4 published records for vendor yardoc.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 17
  2. 19
  3. 24
  4. 26

Bar: total · dark part: CISA KEV.

All records

4 records
  • lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attac

    HighCVSS 7.5No exploitEPSS 3%

    yardoc · yardNov 28, 2017

  • yard before 0.9.20 allows path traversal.

    HighCVSS 7.5No exploitEPSS 2%

    yardoc · yardJul 29, 2019

  • yard: Possible arbitrary path traversal and file access via yard server

    MediumCVSS 6.9No exploitEPSS 1%

    yardoc · yardMay 8, 2026

  • YARD's default template vulnerable to Cross-site Scripting in generated frames.html

    MediumCVSS 6.1No exploitEPSS 1%

    yardoc · yardFeb 28, 2024