Saleor

Saleor

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.55%
  • Veröffentlicht 18.09.2026 18:15:10
  • Zuletzt bearbeitet 18.09.2026 20:17:33

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive au...

  • EPSS 0.44%
  • Veröffentlicht 18.08.2026 17:11:42
  • Zuletzt bearbeitet 18.09.2026 20:09:01

Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as sufficient proof of account ownership and automatically associates anonymous commerce data with the newly a...

  • EPSS 0.28%
  • Veröffentlicht 18.08.2026 17:10:05
  • Zuletzt bearbeitet 18.09.2026 20:09:01

Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can incorrectly authorize unauthenticated GraphQL requests. The flaw permits anonymous callers to use the c...

  • EPSS 0.24%
  • Veröffentlicht 08.04.2026 17:33:37
  • Zuletzt bearbeitet 24.07.2026 21:10:00

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed in 3.23.0a...

  • EPSS 0.29%
  • Veröffentlicht 08.04.2026 17:24:39
  • Zuletzt bearbeitet 24.07.2026 21:10:00

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found in the account email change workflow, the confirmation flow did not verify that the email change confi...

  • EPSS 0.27%
  • Veröffentlicht 08.04.2026 17:22:10
  • Zuletzt bearbeitet 24.07.2026 21:10:00

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in a single API call using aliases or chaining multiple mutations, resulting in resource ...

  • EPSS 0.44%
  • Veröffentlicht 08.04.2026 17:07:57
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multiple GraphQL operations in a single HTTP request as a JSON array but wasn't enforcing any upper limit on...

  • EPSS 0.36%
  • Veröffentlicht 23.01.2026 23:38:31
  • Zuletzt bearbeitet 12.02.2026 16:15:00

Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct Object Reference (IDOR) vulnerability that allows unauthenticated actors to extract sensitive inform...

  • EPSS 0.23%
  • Veröffentlicht 21.01.2026 21:36:19
  • Zuletzt bearbeitet 29.01.2026 18:19:14

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff users or Apps to upload arbitrary files, including malicious HTML and SVG files containing Javascript...

  • EPSS 0.21%
  • Veröffentlicht 21.01.2026 21:31:14
  • Zuletzt bearbeitet 29.01.2026 18:17:46

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor was allowing users to modify rich text fields with HTML without running any backend HTML cleaners thus allowing malicious actors ...