Known vulnerabilities in spree_api
Vendor:
Spree Commerce
Software:
spree_api
Software CPE:
cpe:2.3:a:spree_commerce:spree_api:*:*:*:*:*:*:*:*
Website:
https://spreecommerce.org/
Total vulnerabilities:
6
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
5.6.1
5.6.0
5.5.4
5.4.4
5.5.3
5.5.2
5.5.1
5.5.0
5.4.3
5.3.6
5.2.8
5.4.2
5.4.1
5.4.0
5.3.5
5.3.4
5.3.3
4.10.3
5.3.2
5.2.7
5.1.10
5.0.8
5.3.1
5.3.0
5.2.6
4.10.1
5.2.5
5.1.9
5.0.7
4.10.2
5.2.4
5.2.3
5.2.2
5.2.1
5.2.0
5.1.8
5.1.7
5.1.6
5.1.5
5.0.6
5.1.4
5.1.3
5.1.2
5.1.1
5.1.0
5.0.5
5.0.4
5.0.3
5.0.2
5.0.1
5.0.0
4.10.0
4.9.0
4.8.3
4.8.2
4.8.1
4.8.0
4.7.3
4.6.6
4.5.5
4.7.2
4.6.5
4.5.4
4.4.1
4.3.3
4.2.7
4.1.15
4.0.9
4.7.1
4.6.4
4.7.0
4.6.3
4.6.2
4.6.1
4.6.0
4.5.3
4.5.2
4.5.1
4.5.0
4.3.2
4.2.6
4.4.0
4.3.1
4.3.0
4.0.8
4.1.14
4.2.5
3.7.14.1
4.0.7.1
4.1.13.1
4.2.3.1
4.2.3
4.2.2
4.0.7
4.2.1
3.7.14
4.2.0
0.2.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
0.10.0
0.10.1
0.10.2
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.11.99
0.30.0
0.30.1
0.30.2
0.40.0
0.40.1
0.40.2
0.40.3
0.40.4
0.50.0
0.50.1
0.50.2
0.50.3
0.50.4
0.60.0
0.60.1
0.60.2
0.60.3
0.60.4
0.60.5
0.60.6
0.70.0
0.70.1
0.70.2
0.70.3
0.70.4
0.70.5
0.70.6
0.70.7
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.10
2.0.11
2.0.12
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.10
2.1.11
2.1.12
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.3.10
2.3.11
2.3.12
2.3.13
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.4.10
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.6.1
3.0.7
3.0.8
3.0.9
3.0.10
3.1.0
3.1.1
4.1.12
4.1.11
4.1.10
4.1.9
4.1.8
4.1.7
4.1.6
4.1.5
4.1.4
4.1.3
4.1.2
4.1.1
4.1.0
4.0.5
4.0.4
4.0.3
4.0.2
4.0.1
4.0.0
3.7.13
3.7.12
3.7.11
3.7.10
3.7.9
3.7.8
3.7.6
3.7.5
3.7.4
3.7.3
3.7.2
3.7.1
3.7.0
3.6.6
3.6.5
3.6.4
3.6.3
3.6.2
3.6.1
3.6.0
3.5.0
3.4.6
3.4.5
3.4.4
3.4.3
3.4.2
3.4.1
3.4.0
3.3.6
3.3.5
3.3.4
3.3.3
3.3.1
3.3.0
3.2.9
3.2.8
3.2.7
3.2.6
3.2.4
3.2.3
3.2.2
3.2.1
3.2.0
3.1.14
3.1.13
3.1.12
3.1.11
3.1.10
3.1.8
3.1.7
3.1.6
3.1.5
3.1.4
3.1.3
3.1.2
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU128102 - Authorization Bypass Through User-Controlled Key CVE-2026-22589 |
CWE-639 | Medium | 4.10.2, 5.0.7, 5.1.9, 5.2.5 | 27.04.2026 |
SB2026042781 |
||
| #VU128101 - Authorization Bypass Through User-Controlled Key CVE-2026-22588 |
CWE-639 | Low | 4.10.2, 5.0.7, 5.1.9, 5.2.5 | 27.04.2026 |
SB2026042781 |
||
| #VU122457 - Authorization Bypass Through User-Controlled Key CVE-2026-25757 |
CWE-639 | Medium | 5.0.8, 5.1.10, 5.2.7, 5.3.2 | 09.02.2026 |
SB2026020926 |
||
| #VU122456 - Improper Access Control CVE-2026-25758 |
CWE-284 | Medium | 4.10.3, 5.0.8, 5.1.10, 5.2.7, 5.3.2 | 09.02.2026 |
SB2026020926 |
||
| #VU48656 - Exposure of sensitive information to an unauthorized actor CVE-2020-26223 |
CWE-200 | Medium | 3.7.13, 4.0.5, 4.1.12 | 13.11.2020 |
SB2020112511 |
||
| #VU128100 - Improper Authorization CVE-2020-15269 |
CWE-285 | Low | 3.7.11, 4.0.4, 4.1.11 | 20.10.2020 |
SB2020102068 |