CVE-2019-16676: Plataformatec Simple Form

Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.

Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked as a method call.

Affected products

Published 2019-09-30. Last modified 2026-06-17.