Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2210572
AlmaLinux
5931
Alpaquita
16087
Alpine
4608
Android
3677
Azure Linux
17651
BellSoft Hardened Containers
754
Bitnami
9325
Chainguard
1030811
CleanStart
3846
CRAN
14
crates.io
2738
Debian
68540
Echo
7457
GHC
3
GIT
108258
GitHub Actions
55
Go
9245
Hackage
33
Hex
364
Julia
1713
Linux
29974
Mageia
6232
Maven
7044
MinimOS
145008
npm
228859
NuGet
1869
opam
29
openEuler
8800
openSUSE
14480
OSS-Fuzz
4013
Packagist
7098
Pub
11
PyPI
25182
Red Hat
23387
Rocky Linux
4305
Root
19581
RubyGems
5326
SUSE
23350
SwiftURL
60
TuxCare
9606
Ubuntu
65406
VSCode
21
Wolfi
289821
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-4825-p4xm-pcf2
RubyGems/spree_api
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
22 Sep
Fix available
Severity - 7.1 (High)
CVE-2026-94462
github.com/spree/spree
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
22 Sep
Fix available
Severity - 7.1 (High)
GHSA-xf4v-w5x5-pv79
RubyGems/spree
Spree: CSV Formula Injection in Customer Export
04 Jun
Fix available
Severity - 5.2 (Medium)
CVE-2026-25757
github.com/spree/spree
Unauthenticated Spree Commerce users can view completed guest orders by Order ID
06 Feb
Fix available
Severity - 7.7 (High)
CVE-2026-25758
github.com/spree/spree
Spree allows unauthenticated users can access all guest addresses
06 Feb
Fix available
Severity - 7.7 (High)
GHSA-87fh-rc96-6fr6
RubyGems/spree_api
Unauthenticated Spree Commerce users can access all guest addresses
05 Feb
Fix available
Severity - 7.7 (High)
GHSA-p6pv-q7rc-g4h9
RubyGems/spree_storefront
Unauthenticated Spree Commerce users can view completed guest orders by Order ID
05 Feb
Fix available
Severity - 7.7 (High)
CVE-2026-22589
github.com/spree/spree
Spree API has Unauthenticated IDOR - Guest Address
10 Jan
Fix available
Severity - 7.5 (High)
GHSA-3ghg-3787-w2xr
RubyGems/spree_core
Spree API has Unauthenticated IDOR - Guest Address
08 Jan
Fix available
Severity - 7.5 (High)
GHSA-g268-72p7-9j6j
RubyGems/spree_api
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
08 Jan
Fix available
Severity - 6.5 (Medium)
CVE-2026-22588
github.com/spree/spree
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
08 Jan
Fix available
Severity - 6.5 (Medium)
GHSA-x485-rhg3-cqr4
RubyGems/rd_searchlogic
RubyGems/spree
Spree Commerce is vulnerable to RCE through Search API
20 Aug 2025
Fix available
Severity - 9.3 (Critical)
GHSA-97vm-c39p-jr86
RubyGems/spree
Spree has Remote Command Execution vulnerability in search functionality
13 Aug 2025
Fix available
Severity - 10.0 (Critical)
GHSA-7h48-m3rw-vr27
RubyGems/spree
Spree does not properly restrict the use of a hash to provide values for a model's attributes
17 May 2022
Fix available
GHSA-g466-57gh-cqfw
RubyGems/spree
Spree uses a hardcoded hash value
17 May 2022
Fix available
GHSA-jp57-9j37-5476
RubyGems/spree_auth_devise
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
17 May 2022
Fix available
Load more...
Vulnerability Database - OSV