This is a list of known CVEs relevant for Rails LTS 2.3+. All CVEs are fixed in all versions of Rails LTS (or may not affect some versions). If a versions of Rails LTS is not mentioned, the fix was already done in an official release Ruby on Rails release, and is therefore also part of Rails LTS.
XSS vulnerability in the translate helper method in Ruby on Rails
Possible XSS Security Vulnerability in SafeBuffer#[]
CVE-2012-1099
CVE-2012-2660
CVE-2012-2661
CVE-2012-2694
CVE-2012-2695
CVE-2012-3424
CVE-2012-3463
CVE-2012-3464
CVE-2012-3465
CVE-2012-5664 (a.k.a. CVE-2012-6496)
CVE-2013-0155
CVE-2013-0156
CVE-2013-0276
CVE-2013-0277
CVE-2013-1855
CVE-2013-1856
CVE-2013-1857
CVE-2013-1854
CVE-2013-3221
CVE-2013-4491
CVE-2013-6414
CVE-2013-6415
CVE-2013-6417
CVE-2013-6416
CVE-2014-0080
CVE-2014-0081
CVE-2014-0082
CVE-2014-0130
CVE-2014-3482
CVE-2014-3483
CVE-2014-3514
CVE-2014-7818
CVE-2014-7829
CVE-2015-1840
CVE-2015-3224
CVE-2015-3226
CVE-2015-3227
Start of support for Rails 3.2 LTS. Earlier CVEs are all addressed.
CVE-2015-7576
CVE-2015-7577
CVE-2015-7578
CVE-2015-7579
CVE-2015-7580
CVE-2015-7581
CVE-2016-0751
CVE-2016-0752
CVE-2016-0753
CVE-2016-2097
CVE-2016-2098
CVE-2016-6316
CVE-2016-6317
CVE-2018-8048
CVE-2018-3760
CVE-2018-16468
CVE-2018-16471
Start of support for Rails 4.2 LTS. Earlier CVEs are all addressed.
CVE-2018-16476
CVE-2018-16477
CVE-2019-5418
CVE-2019-5419
CVE-2019-5420
CVE-2019-16782 / CVE-2019-25025
CVE-2020-5267
CVE-2020-10663
json
2.3.0 or later.CVE-2020-8130
CVE-2020-8151
CVE-2020-8159
CVE-2020-8161
CVE-2020-8162
CVE-2020-8163
CVE-2020-8164
CVE-2020-8165
CVE-2020-8166
CVE-2020-8167
CVE-2020-8184
CVE-2020-15169
CVE-2021-22880
CVE-2021-22881
CVE-2021-22885
CVE-2021-22902
CVE-2021-22903
CVE-2021-22904
Start of support for Rails 5.2 LTS. Earlier CVEs are all addressed.
CVE-2022-3704
CVE-2022-23633
CVE-2022-21831
CVE-2022-22577
CVE-2022-27777
CVE-2022-30122
CVE-2022-30123
CVE-2022-31163
CVE-2022-32224
CVE-2022-22795
CVE-2022-44566
CVE-2022-44570
CVE-2022-44571
CVE-2022-44572
CVE-2023-22792
CVE-2023-22794
CVE-2023-22795
CVE-2023-22796
CVE-2023-22797
CVE-2023-22799
CVE-2023-23913
rails_ujs
using the asset pipeline.CVE-2023-27530
CVE-2023-27539
CVE-2023-28120
CVE-2023-28755
uri
library.CVE-2023-28756
time
library.