CVE-2013-6459: Mislav Marohnic Will Paginate

Medium severity, CVSS 4.3. EPSS: 2.2% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the will_paginate gem before 3.0.5 for Ruby allows remote attackers to inject arbitrary web script or HTML via vectors involving generated pagination links.

Affected products

  • Mislav Marohnic Will Paginate: up to and including 3.0.4; version 3.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only

Published 2013-12-31. Last modified 2026-06-17.