« Back to list

Spreecommerce

Spreecommerce Spree: vulnerabilities and CVEs

Spreecommerce Spree has 12 published vulnerabilities, 4 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs12
Last 12 months4
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-25757High (7.7)0.50%—Feb 6, 2026
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed guest orders by Order ID. This issue may lead to…
CVE-2026-25758High (7.7)0.69%—Feb 6, 2026
Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bind arbitrary guest addresses to their…
CVE-2026-22589High (7.5)0.44%—Jan 10, 2026
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that…
CVE-2026-22588Medium (6.5)0.41%—Jan 8, 2026
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Authenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows…
CVE-2011-10026Critical (9.3)2.6%—Aug 20, 2025
Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the…
CVE-2011-10019Critical (10)4.0%—Aug 13, 2025
Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is…
CVE-2020-26223Medium (6.5)1.1%—Nov 13, 2020
Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator…
CVE-2013-2506Medium (4)1.3%—Mar 8, 2013
app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles…
CVE-2013-1656Medium (4.3)1.5%—Mar 8, 2013
Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) payment_method parameter to…
CVE-2008-7311Medium (5)1.2%—Apr 5, 2012
The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection…
CVE-2008-7310Medium (5)1.2%—Apr 5, 2012
Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL,…
CVE-2010-3978Medium (5)2.5%—Nov 17, 2010
Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via…

Other products by Spreecommerce