saleor
PyPI6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting saleorpage 1 of 1
- CVE-2019-13594HIGHCVSS 8.8EG 8.8fixed in 2.8.02019-07-14
vulnerable: 2.7.0
In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.
- CVE-2020-7964MEDIUMCVSS 5.3EG 5.3fixed in 2.9.12020-01-24
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, an…
- CVE-2022-0932MEDIUMCVSS 6.5EG 6.5fixed in 3.1.22022-03-11
vulnerable: 2.10.1
Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.
- CVE-2023-26051MEDIUMCVSS 6.5EG 6.5fixed in 3.1.48, 3.11.12, 3.10.14, 3.9.27, 3.8.30 or 3.7.59, by version range2023-03-02
vulnerable: 2.10.1
Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive in…
- CVE-2023-26052LOWCVSS 3.7EG 3.7fixed in 3.1.48, 3.11.12, 3.10.14, 3.9.27, 3.8.30 or 3.7.59, by version range2023-03-02
vulnerable: 2.10.1
Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive in…
- CVE-2024-29888MEDIUMCVSS 4.2EG 4.2fixed in 3.14.61, 3.15.37, 3.16.34, 3.17.32, 3.18.28 or 3.19.15, by version range2024-03-27
Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which …
Check whether saleor is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for saleor CVEs against the assets you own.
Book a Demo →