CVE-2015-2784: Papercrop Project Papercrop
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
The papercrop gem before 0.3.0 for Ruby on Rails does not properly handle crop input.
Affected products
- Papercrop Project Papercrop: before 0.3.0 (fixed in 0.3.0)
Published 2020-01-21. Last modified 2026-06-17.