Записи vendure
3 опубликованных записей вендора vendure.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 66,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation1
- CWE-202 Exposure of Sensitive Information Through Data Queries1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
3 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
54В плане | CVE-2024-48914Proof of concept | Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategyvendure-ecommerce · vendure · CWE-20 | Критическая9,1 | — | 60,4 % | 15 окт. 2024 г. |
21Наблюдать | CVE-2022-23065Эксплойта нет | Vendure - XSS via SVG File Uploadvendure · vendure · CWE-79 | Средняя5,4 | — | 0,6 % | 2 мая 2022 г. |
10Наблюдать | CVE-2026-25050Proof of concept | Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategyvendure · vendure · CWE-202 | Низкая2,7 | — | 0,4 % | 30 янв. 2026 г. |
- CVE-2024-4891454В плане
Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
КритическаяCVSS 9,1Proof of conceptEPSS 60 %vendure-ecommerce · vendure15 окт. 2024 г.
- CVE-2022-2306521Наблюдать
Vendure - XSS via SVG File Upload
СредняяCVSS 5,4Эксплойта нетEPSS 1 %vendure · vendure2 мая 2022 г.
- CVE-2026-2505010Наблюдать
Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy
НизкаяCVSS 2,7Proof of conceptEPSS 0 %vendure · vendure30 янв. 2026 г.