Skip to content
Noroxi

Spreecommerce records

13 published records for vendor spreecommerce.

Researcher profile

Entered KEV
0 · 0%
Weaponized
2 · 15.4%
Pre-auth RCE
3
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

13 records
  • Spreecommerce < 0.60.2 Search Parameter RCE

    CriticalCVSS 10.0WeaponizedEPSS 4%

    spreecommerce · spreeAug 13, 2025

  • Spreecommerce < 0.50.x API RCE

    CriticalCVSS 9.3WeaponizedEPSS 3%

    spreecommerce · spreeAug 20, 2025

  • Authentication Bypass by CSRF Weakness

    HighCVSS 8.8No exploitEPSS 1%

    spreecommerce · spree auth deviseNov 17, 2021

  • Spree allows unauthenticated users can access all guest addresses

    HighCVSS 7.7No exploitEPSS 1%

    spreecommerce · spreeFeb 6, 2026

  • Unauthenticated Spree Commerce users can view completed guest orders by Order ID

    HighCVSS 7.7No exploitEPSS 0%

    spreecommerce · spreeFeb 6, 2026

  • Spree API has Unauthenticated IDOR - Guest Address

    HighCVSS 7.5No exploitEPSS 0%

    spreecommerce · spreeJan 10, 2026

  • Authorization bypass in Spree

    MediumCVSS 6.5No exploitEPSS 1%

    spreecommerce · spreeNov 13, 2020

  • Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification

    MediumCVSS 6.5No exploitEPSS 0%

    spreecommerce · spreeJan 8, 2026

  • CVE-2010-3978
    21Monitor

    Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validatin

    MediumCVSS 5.0No exploitEPSS 3%

    spreecommerce · spreeNov 17, 2010

  • CVE-2008-7310
    20Monitor

    Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set th

    MediumCVSS 5.0No exploitEPSS 1%

    spreecommerce · spreeApr 5, 2012

  • CVE-2008-7311
    20Monitor

    The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which

    MediumCVSS 5.0No exploitEPSS 1%

    spreecommerce · spreeApr 5, 2012

  • CVE-2013-1656
    17Monitor

    Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary co

    MediumCVSS 4.3No exploitEPSS 2%

    spreecommerce · spreeMar 8, 2013

  • CVE-2013-2506
    16Monitor

    app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when upd

    MediumCVSS 4.0No exploitEPSS 1%

    spreecommerce · spreeMar 8, 2013