Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-4825-p4xm-pcf2
  • RubyGems/spree_api
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR) 22 Sep
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-94462
  • github.com/spree/spree
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR) 22 Sep
  • Fix available
  • Severity - 7.1 (High)
GHSA-xf4v-w5x5-pv79
  • RubyGems/spree
Spree: CSV Formula Injection in Customer Export 04 Jun
  • Fix available
  • Severity - 5.2 (Medium)
CVE-2026-25757
  • github.com/spree/spree
Unauthenticated Spree Commerce users can view completed guest orders by Order ID 06 Feb
  • Fix available
  • Severity - 7.7 (High)
CVE-2026-25758
  • github.com/spree/spree
Spree allows unauthenticated users can access all guest addresses 06 Feb
  • Fix available
  • Severity - 7.7 (High)
GHSA-87fh-rc96-6fr6
  • RubyGems/spree_api
Unauthenticated Spree Commerce users can access all guest addresses 05 Feb
  • Fix available
  • Severity - 7.7 (High)
GHSA-p6pv-q7rc-g4h9
  • RubyGems/spree_storefront
Unauthenticated Spree Commerce users can view completed guest orders by Order ID 05 Feb
  • Fix available
  • Severity - 7.7 (High)
CVE-2026-22589
  • github.com/spree/spree
Spree API has Unauthenticated IDOR - Guest Address 10 Jan
  • Fix available
  • Severity - 7.5 (High)
GHSA-3ghg-3787-w2xr
  • RubyGems/spree_core
Spree API has Unauthenticated IDOR - Guest Address 08 Jan
  • Fix available
  • Severity - 7.5 (High)
GHSA-g268-72p7-9j6j
  • RubyGems/spree_api
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification 08 Jan
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-22588
  • github.com/spree/spree
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification 08 Jan
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-x485-rhg3-cqr4
  • RubyGems/rd_searchlogic
  • RubyGems/spree
Spree Commerce is vulnerable to RCE through Search API 20 Aug 2025
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-97vm-c39p-jr86
  • RubyGems/spree
Spree has Remote Command Execution vulnerability in search functionality 13 Aug 2025
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-7h48-m3rw-vr27
  • RubyGems/spree
Spree does not properly restrict the use of a hash to provide values for a model's attributes 17 May 2022
  • Fix available
GHSA-g466-57gh-cqfw
  • RubyGems/spree
Spree uses a hardcoded hash value 17 May 2022
  • Fix available
GHSA-jp57-9j37-5476
  • RubyGems/spree_auth_devise
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles 17 May 2022
  • Fix available