Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
RubyGems/spree — 7 CVEs · VulnScope
pkg:RubyGems/
spree
7 total CVEs
CRITICAL
1
HIGH
1
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.8
CVE-2011-10019
Spree has Remote Command Execution vulnerability in search functionality
from 0, < 0.60.2
HIGH
7.4
CVE-2020-15269
Ensure that doorkeeper_token is valid when authenticating requests in API v2 calls
from 0, < 3.7.11
—
CVE-2011-10026
Spree Commerce is vulnerable to RCE through Search API
>= 0.30.0.beta1, < 0.50.0
—
Spree does not properly restrict the use of a hash to provide values for a model's attributes
from 0, < 0.4.0
—
Spree uses a hardcoded hash value
from 0, < 0.4.0
—
Spree allows remote attackers to obtain sensitive information
>= 0.11.0, < 0.11.2
—
Spree Improper Input Validation vulnerability
>= 1.0.0, < 2.0.0.rc1
CVE-2008-7310
CVE-2008-7311
CVE-2010-3978
CVE-2013-1656