Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-25757 Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can vi… Spree 5.0.8 / 5.1.10+ Fix from $1,6002026-02-06 HIGH 7.5 CVE-2026-25758 Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow th… Spree 4.10.3 / 5.0.8+ Fix from $1,9502026-02-06 HIGH 7.5 CVE-2026-22589 Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure … Spree 4.10.2 / 5.0.7+ Fix from $1,9502026-01-10 MEDIUM 6.5 CVE-2026-22588 Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Authenticated Insecure Di… Spree 4.10.2 / 5.0.7+ Fix from $1,6002026-01-08 CRITICAL 9.8 CVE-2011-10026 Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation … Spree 0.50.1+ Fix from $2,3002025-08-20 CRITICAL 9.8 CVE-2011-10019 Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to proper… Spree 0.60.2+ Fix from $2,3002025-08-13 HIGH 8.8 CVE-2021-41275 spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by u… Spree Auth Devise 4.4.1+ Fix from $1,9502021-11-17 MEDIUM 6.5 CVE-2020-26223 Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12… Spree 3.7.13 / 4.0.5+ Fix from $1,6002020-11-13 MEDIUM 5.0 CVE-2008-7310 Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order s… Spree Mitigation only Fix from $1,6002012-04-05 MEDIUM 5.0 CVE-2008-7311 The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it … Spree Mitigation only Fix from $1,6002012-04-05 MEDIUM 5.0 CVE-2010-3978 Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating request… Spree Patch available Fix from $1,6002010-11-17