Skip to main content

Vendor archive

nebulab CVEs

Beta · best-effort

5 CVEs tagged to vendor nebulab1 Critical, 1 High, 2 Medium, 1 Low, 0 Unrated.

CVE-2022-31000

Published Jun 1, 2022

solidus_backend is the admin interface for the Solidus e-commerce framework. Versions prior to 3.1.6, 3.0.6, and 2.11.16 contain a cross-site request forgery (CSRF) vulnerability.…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-43846

Published Dec 20, 2021

`solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior to 3.1.5, 3.0.5, and 2.11.14 contain a cross-site request fo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43805

Published Dec 7, 2021

Solidus is a free, open-source ecommerce platform built on Rails. Versions of Solidus prior to 3.1.4, 3.0.4, and 2.11.13 have a denial of service vulnerability that could be explo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41274

Published Nov 17, 2021

solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devise is subject to a CSRF vulner…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15109

Published Aug 4, 2020

In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerability allows a malicious custo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1