Spreecommerce
Spreecommerce Spree: vulnerabilidades y CVE
Spreecommerce Spree tiene 12 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses4
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-25757 | Alta (7.7) | 0.50% | — | 6 feb 2026 | Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed guest orders by Order ID. This issue may lead to… |
| CVE-2026-25758 | Alta (7.7) | 0.69% | — | 6 feb 2026 | Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bind arbitrary guest addresses to their… |
| CVE-2026-22589 | Alta (7.5) | 0.44% | — | 10 ene 2026 | Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that… |
| CVE-2026-22588 | Media (6.5) | 0.41% | — | 8 ene 2026 | Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Authenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows… |
| CVE-2011-10026 | Crítica (9.3) | 2.6% | — | 20 ago 2025 | Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the… |
| CVE-2011-10019 | Crítica (10) | 4.0% | — | 13 ago 2025 | Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is… |
| CVE-2020-26223 | Media (6.5) | 1.1% | — | 13 nov 2020 | Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator… |
| CVE-2013-2506 | Media (4) | 1.3% | — | 8 mar 2013 | app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles… |
| CVE-2013-1656 | Media (4.3) | 1.5% | — | 8 mar 2013 | Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) payment_method parameter to… |
| CVE-2008-7311 | Media (5) | 1.2% | — | 5 abr 2012 | The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection… |
| CVE-2008-7310 | Media (5) | 1.2% | — | 5 abr 2012 | Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL,… |
| CVE-2010-3978 | Media (5) | 2.5% | — | 17 nov 2010 | Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via… |