Skip to main content

Vendor archive

saleor CVEs

Beta · best-effort

16 CVEs tagged to vendor saleor0 Critical, 5 High, 10 Medium, 1 Low, 0 Unrated.

CVE-2026-39851

Published Apr 8, 2026

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided em…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-35407

Published Apr 8, 2026

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found in the account email change wor…

CVSS 5.9 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-35401

Published Apr 8, 2026

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in a single API ca…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33756

Published Apr 8, 2026

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multiple GraphQL operations in a sing…

CVSS 7.5 · High
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-24136

Published Jan 24, 2026

Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct Object Reference (IDOR) vulne…

CVSS 8.7 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-23499

Published Jan 21, 2026

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff users or Apps to upload arbitr…

CVSS 8.5 · High
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-22849

Published Jan 21, 2026

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor was allowing users to modify rich text fields with HTML wi…

CVSS 7.2 · High
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2024-31205

Published Apr 8, 2024

Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19, an attacker may bypass cross-set reque…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29888

Published Mar 27, 2024

Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-collect as a delivery method in specific conditions the custome…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29036

Published Mar 20, 2024

Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3294

Published Jun 16, 2023

Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32694

Published May 25, 2023

Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing attacks. Malicious users could abuse this vulnerability on…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26052

Published Mar 2, 2023

Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-26051

Published Mar 2, 2023

Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39275

Published Oct 6, 2022

Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking the ID type input which allowed to access database objects…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0932

Published Mar 11, 2022

Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1