Skip to main content

Vendor/product archive

spreecommerce / spree CVEs

Beta · best-effort

12 CVEs tagged to spreecommerce / spree2 Critical, 4 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2026-25757

Published Feb 6, 2026

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed guest orders by O…

CVSS 7.7 · High
evidence mentions
9
Buzz score
33.0
Vendor/product tagsBeta · best-effort

CVE-2026-25758

Published Feb 6, 2026

Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bi…

CVSS 7.7 · High
evidence mentions
11
Buzz score
34.9
Vendor/product tagsBeta · best-effort

CVE-2026-22589

Published Jan 10, 2026

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR)…

CVSS 7.5 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-22588

Published Jan 8, 2026

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Authenticated Insecure Direct Object Reference (IDOR) v…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2011-10026

Published Aug 20, 2025

Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arb…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-10019

Published Aug 13, 2025

Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-26223

Published Nov 13, 2020

Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization by…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2506

Published Mar 8, 2013

app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authe…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1656

Published Mar 8, 2013

Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) payment_method param…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7311

Published Apr 5, 2012

The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7310

Published Apr 5, 2012

Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the inte…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3978

Published Nov 17, 2010

Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attacke…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1