spree_api
RubyGems4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting spree_apipage 1 of 1
- CVE-2020-26223HIGHCVSS 7.7EG 7.7fixed in 3.7.13, 4.0.5 or 4.1.12, by version range2020-11-13
vulnerable: 4.1.0 ... 4.1.9 (12 versions)
Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 O…
- CVE-2026-22588MEDIUMCVSS 6.5EG 6.5fixed in 4.10.2, 5.0.7, 5.1.9 or 5.2.5, by version range2026-01-08
vulnerable: 5.2.0, 5.2.1, 5.2.2, 5.2.3, 5.2.4
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Authenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an authenticated use…
- CVE-2026-25758HIGHCVSS 7.5EG 7.5fixed in 4.10.3, 5.0.8, 5.1.10, 5.2.7 or 5.3.2, by version range2026-02-06
vulnerable: 5.3.0, 5.3.1
Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bind arbitrary guest addresses to their order by manipulating …
- CVE-2026-94462HIGHCVSS 7.1EG 7.1fixed in 5.4.4 or 5.5.4, by version range2026-09-22
vulnerable: 5.5.0, 5.5.1, 5.5.2, 5.5.3
Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associate in Spree::Api::V3::Store::CartsController#associate uses find_cart_for_association to locate a …
Check whether spree_api is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for spree_api CVEs against the assets you own.
Book a Demo →