Releases86
Frequency1 month 3 weeks
Last Release
Stars6.53K
Create beautiful JavaScript charts with one line of Ruby

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM4.3 MEDIUM

The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).

7.3 HIGH7.5 HIGH

Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution.

2.6 LOW

The Chartkick gem through 3.1.0 for Ruby allows XSS.