saleor
PyPI6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting saleorpage 1 of 1
- CVE-2019-13594HIGHCVSS 8.8EG 8.8✓ Fixed in 2.8.02019-07-14
vulnerable: 2.7.0
In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.
- CVE-2020-7964MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.9.12020-01-24
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, an…
- CVE-2022-0932MEDIUMCVSS 6.5EG 6.5✓ Fixed in 3.1.22022-03-11
vulnerable: 2.10.1
Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.
- CVE-2023-26051MEDIUMCVSS 6.5EG 6.5✓ Fixed in 3.7.592023-03-02
Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive in…
- CVE-2023-26052LOWCVSS 3.7EG 3.7✓ Fixed in 3.7.592023-03-02
Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive in…
- CVE-2024-29888MEDIUMCVSS 4.2EG 4.2✓ Fixed in 3.19.152024-03-27
Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which …
Check whether saleor is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for saleor CVEs against the assets you own.
Start Free Scan →