Spreecommerce records
13 published records for vendor spreecommerce.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 15.4%
- Pre-auth RCE
- 3
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-255 Credentials Management Errors2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-284 Improper Access Control1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2011-10019Weaponized | Spreecommerce < 0.60.2 Search Parameter RCEspreecommerce · spree · CWE-94 | Critical10.0 | — | 4.0% | Aug 13, 2025 |
38Monitor | CVE-2011-10026Weaponized | Spreecommerce < 0.50.x API RCEspreecommerce · spree · CWE-78 | Critical9.3 | — | 2.6% | Aug 20, 2025 |
35Monitor | CVE-2021-41275No exploit | Authentication Bypass by CSRF Weaknessspreecommerce · spree auth devise · CWE-352 | High8.8 | — | 0.6% | Nov 17, 2021 |
30Monitor | CVE-2026-25758No exploit | Spree allows unauthenticated users can access all guest addressesspreecommerce · spree · CWE-284 | High7.7 | — | 0.7% | Feb 6, 2026 |
30Monitor | CVE-2026-25757No exploit | Unauthenticated Spree Commerce users can view completed guest orders by Order IDspreecommerce · spree · CWE-639 | High7.7 | — | 0.5% | Feb 6, 2026 |
30Monitor | CVE-2026-22589No exploit | Spree API has Unauthenticated IDOR - Guest Addressspreecommerce · spree · CWE-639 | High7.5 | — | 0.4% | Jan 10, 2026 |
26Monitor | CVE-2020-26223No exploit | Authorization bypass in Spreespreecommerce · spree · CWE-863 | Medium6.5 | — | 1.1% | Nov 13, 2020 |
26Monitor | CVE-2026-22588No exploit | Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modificationspreecommerce · spree · CWE-639 | Medium6.5 | — | 0.4% | Jan 8, 2026 |
21Monitor | CVE-2010-3978No exploit | Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validatinspreecommerce · spree · CWE-200 | Medium5.0 | — | 2.5% | Nov 17, 2010 |
20Monitor | CVE-2008-7310No exploit | Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set thspreecommerce · spree · CWE-255 | Medium5.0 | — | 1.2% | Apr 5, 2012 |
20Monitor | CVE-2008-7311No exploit | The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which spreecommerce · spree · CWE-255 | Medium5.0 | — | 1.2% | Apr 5, 2012 |
17Monitor | CVE-2013-1656No exploit | Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary cospreecommerce · spree · CWE-20 | Medium4.3 | — | 1.5% | Mar 8, 2013 |
16Monitor | CVE-2013-2506No exploit | app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updspreecommerce · spree · CWE-264 | Medium4.0 | — | 1.3% | Mar 8, 2013 |
- CVE-2011-1001941Plan
Spreecommerce < 0.60.2 Search Parameter RCE
CriticalCVSS 10.0WeaponizedEPSS 4%spreecommerce · spreeAug 13, 2025
- CVE-2011-1002638Monitor
Spreecommerce < 0.50.x API RCE
CriticalCVSS 9.3WeaponizedEPSS 3%spreecommerce · spreeAug 20, 2025
- CVE-2021-4127535Monitor
Authentication Bypass by CSRF Weakness
HighCVSS 8.8No exploitEPSS 1%spreecommerce · spree auth deviseNov 17, 2021
- CVE-2026-2575830Monitor
Spree allows unauthenticated users can access all guest addresses
HighCVSS 7.7No exploitEPSS 1%spreecommerce · spreeFeb 6, 2026
- CVE-2026-2575730Monitor
Unauthenticated Spree Commerce users can view completed guest orders by Order ID
HighCVSS 7.7No exploitEPSS 0%spreecommerce · spreeFeb 6, 2026
- CVE-2026-2258930Monitor
Spree API has Unauthenticated IDOR - Guest Address
HighCVSS 7.5No exploitEPSS 0%spreecommerce · spreeJan 10, 2026
- CVE-2020-2622326Monitor
Authorization bypass in Spree
MediumCVSS 6.5No exploitEPSS 1%spreecommerce · spreeNov 13, 2020
- CVE-2026-2258826Monitor
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
MediumCVSS 6.5No exploitEPSS 0%spreecommerce · spreeJan 8, 2026
- CVE-2010-397821Monitor
Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validatin
MediumCVSS 5.0No exploitEPSS 3%spreecommerce · spreeNov 17, 2010
- CVE-2008-731020Monitor
Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set th
MediumCVSS 5.0No exploitEPSS 1%spreecommerce · spreeApr 5, 2012
- CVE-2008-731120Monitor
The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which
MediumCVSS 5.0No exploitEPSS 1%spreecommerce · spreeApr 5, 2012
- CVE-2013-165617Monitor
Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary co
MediumCVSS 4.3No exploitEPSS 2%spreecommerce · spreeMar 8, 2013
- CVE-2013-250616Monitor
app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when upd
MediumCVSS 4.0No exploitEPSS 1%spreecommerce · spreeMar 8, 2013