Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Saleor MEDIUM 6.5
CVE-2026-35407

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found i…

Fix: 3.20.118 / 3.21.54+
Fix from $1,600 2026-04-08
Saleor HIGH 7.5
CVE-2026-35401

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations…

Fix: 3.20.118 / 3.21.54+
Fix from $1,950 2026-04-08
Saleor HIGH 7.5
CVE-2026-33756

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multipl…

Fix: 3.20.118 / 3.21.54+
Fix from $1,950 2026-04-08
Saleor HIGH 7.5
CVE-2026-24136

Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct…

Fix: 3.20.110 / 3.21.45+
Fix from $1,950 2026-01-24
Saleor MEDIUM 5.4
CVE-2026-23499

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff …

Fix: 3.20.108 / 3.21.43+
Fix from $1,600 2026-01-21
Saleor MEDIUM 5.4
CVE-2024-31205

Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19, an attac…

Fix: 3.14.64 / 3.15.39+
Fix from $1,600 2024-04-08
Saleor MEDIUM 5.4
CVE-2024-29888

Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-collect as a delivery method in s…

Fix: 3.14.61 / 3.15.37+
Fix from $1,600 2024-03-27
React Storefront MEDIUM 6.5
CVE-2024-29036

Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authentica…

Fix: 1.0.2+
Fix from $1,600 2024-03-20
React Storefront MEDIUM 6.1
CVE-2023-3294

Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7.

Fix: 2023-06-16+
Fix from $1,600 2023-06-16
Saleor MEDIUM 5.4
CVE-2023-32694

Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing attacks. Malicious users coul…

Fix: 3.7.68 / 3.8.40+
Fix from $1,600 2023-05-25
Saleor MEDIUM 5.3
CVE-2023-26052

Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properl…

Fix: 3.1.48 / 3.7.59+
Fix from $1,600 2023-03-02
Saleor MEDIUM 6.5
CVE-2022-0932

Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.

Fix: 3.1.2+
Fix from $1,600 2022-03-11