8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether avo is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.3
CVE-2023-34103
avo vulnerable to Stored XSS (Cross Site Scripting) in html content based fields
HIGH 8.3
CVE-2023-34102
avo possible unsafe reflection / partial DoS vulnerability
MEDIUM 6.5
CVE-2024-22411
Cross-site scripting (XSS) in Action messages on Avo
HIGH 7.3
CVE-2024-22191
avo vulnerable to stored cross-site scripting (XSS) in key_value field
CRITICAL 9.6
CVE-2026-55518
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
MEDIUM 6.5
CVE-2026-53769
Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy
HIGH 8.8
CVE-2026-42205
Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across Resources
UNKNOWN
CVE-2026-33209
Avo has a XSS vulnerability on `return_to` param
Browse more RubyGems advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes