Записи Spreecommerce
13 опубликованных записей вендора spreecommerce.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 15,4 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-255 Credentials Management Errors2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-284 Improper Access Control1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2011-10019Готовый эксплойт | Spreecommerce < 0.60.2 Search Parameter RCEspreecommerce · spree · CWE-94 | Критическая10,0 | — | 4,0 % | 13 авг. 2025 г. |
38Наблюдать | CVE-2011-10026Готовый эксплойт | Spreecommerce < 0.50.x API RCEspreecommerce · spree · CWE-78 | Критическая9,3 | — | 2,6 % | 20 авг. 2025 г. |
35Наблюдать | CVE-2021-41275Эксплойта нет | Authentication Bypass by CSRF Weaknessspreecommerce · spree auth devise · CWE-352 | Высокая8,8 | — | 0,6 % | 17 нояб. 2021 г. |
30Наблюдать | CVE-2026-25758Эксплойта нет | Spree allows unauthenticated users can access all guest addressesspreecommerce · spree · CWE-284 | Высокая7,7 | — | 0,7 % | 6 февр. 2026 г. |
30Наблюдать | CVE-2026-25757Эксплойта нет | Unauthenticated Spree Commerce users can view completed guest orders by Order IDspreecommerce · spree · CWE-639 | Высокая7,7 | — | 0,5 % | 6 февр. 2026 г. |
30Наблюдать | CVE-2026-22589Эксплойта нет | Spree API has Unauthenticated IDOR - Guest Addressspreecommerce · spree · CWE-639 | Высокая7,5 | — | 0,4 % | 10 янв. 2026 г. |
26Наблюдать | CVE-2020-26223Эксплойта нет | Authorization bypass in Spreespreecommerce · spree · CWE-863 | Средняя6,5 | — | 1,1 % | 13 нояб. 2020 г. |
26Наблюдать | CVE-2026-22588Эксплойта нет | Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modificationspreecommerce · spree · CWE-639 | Средняя6,5 | — | 0,4 % | 8 янв. 2026 г. |
21Наблюдать | CVE-2010-3978Эксплойта нет | Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validatinspreecommerce · spree · CWE-200 | Средняя5,0 | — | 2,5 % | 17 нояб. 2010 г. |
20Наблюдать | CVE-2008-7310Эксплойта нет | Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set thspreecommerce · spree · CWE-255 | Средняя5,0 | — | 1,2 % | 5 апр. 2012 г. |
20Наблюдать | CVE-2008-7311Эксплойта нет | The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which spreecommerce · spree · CWE-255 | Средняя5,0 | — | 1,2 % | 5 апр. 2012 г. |
17Наблюдать | CVE-2013-1656Эксплойта нет | Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary cospreecommerce · spree · CWE-20 | Средняя4,3 | — | 1,5 % | 8 мар. 2013 г. |
16Наблюдать | CVE-2013-2506Эксплойта нет | app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updspreecommerce · spree · CWE-264 | Средняя4,0 | — | 1,3 % | 8 мар. 2013 г. |
- CVE-2011-1001941В плане
Spreecommerce < 0.60.2 Search Parameter RCE
КритическаяCVSS 10,0Готовый эксплойтEPSS 4 %spreecommerce · spree13 авг. 2025 г.
- CVE-2011-1002638Наблюдать
Spreecommerce < 0.50.x API RCE
КритическаяCVSS 9,3Готовый эксплойтEPSS 3 %spreecommerce · spree20 авг. 2025 г.
- CVE-2021-4127535Наблюдать
Authentication Bypass by CSRF Weakness
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %spreecommerce · spree auth devise17 нояб. 2021 г.
- CVE-2026-2575830Наблюдать
Spree allows unauthenticated users can access all guest addresses
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %spreecommerce · spree6 февр. 2026 г.
- CVE-2026-2575730Наблюдать
Unauthenticated Spree Commerce users can view completed guest orders by Order ID
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %spreecommerce · spree6 февр. 2026 г.
- CVE-2026-2258930Наблюдать
Spree API has Unauthenticated IDOR - Guest Address
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %spreecommerce · spree10 янв. 2026 г.
- CVE-2020-2622326Наблюдать
Authorization bypass in Spree
СредняяCVSS 6,5Эксплойта нетEPSS 1 %spreecommerce · spree13 нояб. 2020 г.
- CVE-2026-2258826Наблюдать
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
СредняяCVSS 6,5Эксплойта нетEPSS 0 %spreecommerce · spree8 янв. 2026 г.
- CVE-2010-397821Наблюдать
Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validatin
СредняяCVSS 5,0Эксплойта нетEPSS 3 %spreecommerce · spree17 нояб. 2010 г.
- CVE-2008-731020Наблюдать
Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set th
СредняяCVSS 5,0Эксплойта нетEPSS 1 %spreecommerce · spree5 апр. 2012 г.
- CVE-2008-731120Наблюдать
The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which
СредняяCVSS 5,0Эксплойта нетEPSS 1 %spreecommerce · spree5 апр. 2012 г.
- CVE-2013-165617Наблюдать
Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary co
СредняяCVSS 4,3Эксплойта нетEPSS 2 %spreecommerce · spree8 мар. 2013 г.
- CVE-2013-250616Наблюдать
app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when upd
СредняяCVSS 4,0Эксплойта нетEPSS 1 %spreecommerce · spree8 мар. 2013 г.