Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242520
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048512
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68992
Echo
7853
GHC
3
GIT
109121
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148659
npm
229266
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4344
Root
19650
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9974
Ubuntu
66090
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-4825-p4xm-pcf2
RubyGems/spree_api
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
22 Sep
Fix available
Severity - 7.1 (High)
CVE-2026-94462
github.com/spree/spree
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
22 Sep
Fix available
Severity - 7.1 (High)
GHSA-xf4v-w5x5-pv79
RubyGems/spree
Spree: CSV Formula Injection in Customer Export
04 Jun
Fix available
Severity - 5.2 (Medium)
CVE-2026-25757
github.com/spree/spree
Unauthenticated Spree Commerce users can view completed guest orders by Order ID
06 Feb
Fix available
Severity - 7.7 (High)
CVE-2026-25758
github.com/spree/spree
Spree allows unauthenticated users can access all guest addresses
06 Feb
Fix available
Severity - 7.7 (High)
GHSA-87fh-rc96-6fr6
RubyGems/spree_api
Unauthenticated Spree Commerce users can access all guest addresses
05 Feb
Fix available
Severity - 7.7 (High)
GHSA-p6pv-q7rc-g4h9
RubyGems/spree_storefront
Unauthenticated Spree Commerce users can view completed guest orders by Order ID
05 Feb
Fix available
Severity - 7.7 (High)
CVE-2026-22589
github.com/spree/spree
Spree API has Unauthenticated IDOR - Guest Address
10 Jan
Fix available
Severity - 7.5 (High)
GHSA-3ghg-3787-w2xr
RubyGems/spree_core
Spree API has Unauthenticated IDOR - Guest Address
08 Jan
Fix available
Severity - 7.5 (High)
GHSA-g268-72p7-9j6j
RubyGems/spree_api
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
08 Jan
Fix available
Severity - 6.5 (Medium)
CVE-2026-22588
github.com/spree/spree
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
08 Jan
Fix available
Severity - 6.5 (Medium)
GHSA-x485-rhg3-cqr4
RubyGems/rd_searchlogic
RubyGems/spree
Spree Commerce is vulnerable to RCE through Search API
20 Aug 2025
Fix available
Severity - 9.3 (Critical)
GHSA-97vm-c39p-jr86
RubyGems/spree
Spree has Remote Command Execution vulnerability in search functionality
13 Aug 2025
Fix available
Severity - 10.0 (Critical)
GHSA-7h48-m3rw-vr27
RubyGems/spree
Spree does not properly restrict the use of a hash to provide values for a model's attributes
17 May 2022
Fix available
GHSA-g466-57gh-cqfw
RubyGems/spree
Spree uses a hardcoded hash value
17 May 2022
Fix available
GHSA-jp57-9j37-5476
RubyGems/spree_auth_devise
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
17 May 2022
Fix available
Load more...
Vulnerability Database - OSV