Spreecommerce kayıtları
spreecommerce üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %15,4
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-255 Credentials Management Errors2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-284 Improper Access Control1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2011-10019Silahlaştırılmış | Spreecommerce < 0.60.2 Search Parameter RCEspreecommerce · spree · CWE-94 | Kritik10,0 | — | %4,0 | 13 Ağu 2025 |
38İzleyin | CVE-2011-10026Silahlaştırılmış | Spreecommerce < 0.50.x API RCEspreecommerce · spree · CWE-78 | Kritik9,3 | — | %2,6 | 20 Ağu 2025 |
35İzleyin | CVE-2021-41275İstismar yok | Authentication Bypass by CSRF Weaknessspreecommerce · spree auth devise · CWE-352 | Yüksek8,8 | — | %0,6 | 17 Kas 2021 |
30İzleyin | CVE-2026-25758İstismar yok | Spree allows unauthenticated users can access all guest addressesspreecommerce · spree · CWE-284 | Yüksek7,7 | — | %0,7 | 6 Şub 2026 |
30İzleyin | CVE-2026-25757İstismar yok | Unauthenticated Spree Commerce users can view completed guest orders by Order IDspreecommerce · spree · CWE-639 | Yüksek7,7 | — | %0,5 | 6 Şub 2026 |
30İzleyin | CVE-2026-22589İstismar yok | Spree API has Unauthenticated IDOR - Guest Addressspreecommerce · spree · CWE-639 | Yüksek7,5 | — | %0,4 | 10 Oca 2026 |
26İzleyin | CVE-2020-26223İstismar yok | Authorization bypass in Spreespreecommerce · spree · CWE-863 | Orta6,5 | — | %1,1 | 13 Kas 2020 |
26İzleyin | CVE-2026-22588İstismar yok | Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modificationspreecommerce · spree · CWE-639 | Orta6,5 | — | %0,4 | 8 Oca 2026 |
21İzleyin | CVE-2010-3978İstismar yok | Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validatinspreecommerce · spree · CWE-200 | Orta5,0 | — | %2,5 | 17 Kas 2010 |
20İzleyin | CVE-2008-7310İstismar yok | Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set thspreecommerce · spree · CWE-255 | Orta5,0 | — | %1,2 | 5 Nis 2012 |
20İzleyin | CVE-2008-7311İstismar yok | The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which spreecommerce · spree · CWE-255 | Orta5,0 | — | %1,2 | 5 Nis 2012 |
17İzleyin | CVE-2013-1656İstismar yok | Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary cospreecommerce · spree · CWE-20 | Orta4,3 | — | %1,5 | 8 Mar 2013 |
16İzleyin | CVE-2013-2506İstismar yok | app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updspreecommerce · spree · CWE-264 | Orta4,0 | — | %1,3 | 8 Mar 2013 |
- CVE-2011-1001941Planlayın
Spreecommerce < 0.60.2 Search Parameter RCE
KritikCVSS 10,0SilahlaştırılmışEPSS %4spreecommerce · spree13 Ağu 2025
- CVE-2011-1002638İzleyin
Spreecommerce < 0.50.x API RCE
KritikCVSS 9,3SilahlaştırılmışEPSS %3spreecommerce · spree20 Ağu 2025
- CVE-2021-4127535İzleyin
Authentication Bypass by CSRF Weakness
YüksekCVSS 8,8İstismar yokEPSS %1spreecommerce · spree auth devise17 Kas 2021
- CVE-2026-2575830İzleyin
Spree allows unauthenticated users can access all guest addresses
YüksekCVSS 7,7İstismar yokEPSS %1spreecommerce · spree6 Şub 2026
- CVE-2026-2575730İzleyin
Unauthenticated Spree Commerce users can view completed guest orders by Order ID
YüksekCVSS 7,7İstismar yokEPSS %0spreecommerce · spree6 Şub 2026
- CVE-2026-2258930İzleyin
Spree API has Unauthenticated IDOR - Guest Address
YüksekCVSS 7,5İstismar yokEPSS %0spreecommerce · spree10 Oca 2026
- CVE-2020-2622326İzleyin
Authorization bypass in Spree
OrtaCVSS 6,5İstismar yokEPSS %1spreecommerce · spree13 Kas 2020
- CVE-2026-2258826İzleyin
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
OrtaCVSS 6,5İstismar yokEPSS %0spreecommerce · spree8 Oca 2026
- CVE-2010-397821İzleyin
Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validatin
OrtaCVSS 5,0İstismar yokEPSS %3spreecommerce · spree17 Kas 2010
- CVE-2008-731020İzleyin
Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set th
OrtaCVSS 5,0İstismar yokEPSS %1spreecommerce · spree5 Nis 2012
- CVE-2008-731120İzleyin
The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which
OrtaCVSS 5,0İstismar yokEPSS %1spreecommerce · spree5 Nis 2012
- CVE-2013-165617İzleyin
Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary co
OrtaCVSS 4,3İstismar yokEPSS %2spreecommerce · spree8 Mar 2013
- CVE-2013-250616İzleyin
app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when upd
OrtaCVSS 4,0İstismar yokEPSS %1spreecommerce · spree8 Mar 2013