Spreecommerce / Spree
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-25757 | Unauthenticated Spree Commerce users can view completed guest orders by Order ID | HIGH | 7.7 | Feb 6, 2026 |
| CVE-2026-25758 | Spree allows unauthenticated users can access all guest addresses | HIGH | 7.7 | Feb 6, 2026 |
| CVE-2026-22589 | Spree API has Unauthenticated IDOR - Guest Address | HIGH | 7.5 | Jan 10, 2026 |
| CVE-2026-22588 | Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification | MEDIUM | 6.5 | Jan 8, 2026 |
| CVE-2011-10026 | Spreecommerce < 0.50.x API RCE | CRITICAL | 9.3 | Aug 20, 2025 |
| CVE-2011-10019 | Spreecommerce < 0.60.2 Search Parameter RCE | CRITICAL | 10.0 | Aug 13, 2025 |
| CVE-2020-26223 | Authorization bypass in Spree | HIGH | 7.7 | Nov 13, 2020 |
| CVE-2013-2506 | app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which… | MEDIUM | 4.0 | Mar 8, 2013 |
| CVE-2013-1656 | Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1)… | MEDIUM | 4.3 | Mar 8, 2013 |
| CVE-2008-7311 | The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for… | MEDIUM | 5.0 | Apr 4, 2012 |
| CVE-2008-7310 | Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value… | MEDIUM | 5.0 | Apr 4, 2012 |
| CVE-2010-3978 | Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which a… | MEDIUM | 5.0 | Nov 17, 2010 |
Showing 1 to 12 of 12 CVEs