avo vulnerabilities
CVEs whose affected-version data names the avo package (rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-53769Medium· 6.5PoCAvo is a framework to create admin panels for Ruby on Rails apps
Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload…
▾ Twilightavo-hq · avoEPSS 0.25%via NVD
CVE-2026-55518Critical· 9.6Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
▾ Midnightavo · avoEPSS 0.45%via GHSA