CVE-2026-44472
- EPSS 0.44%
- Veröffentlicht 18.08.2026 17:11:42
- Zuletzt bearbeitet 18.08.2026 18:17:33
Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as sufficient proof of account ownership and automatically associates anonymous commerce data with the newly a...
CVE-2026-48744
- EPSS 0.28%
- Veröffentlicht 18.08.2026 17:10:05
- Zuletzt bearbeitet 19.08.2026 19:17:17
Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can incorrectly authorize unauthenticated GraphQL requests. The flaw permits anonymous callers to use the c...
CVE-2026-39851
- EPSS 0.24%
- Veröffentlicht 08.04.2026 17:33:37
- Zuletzt bearbeitet 24.07.2026 21:10:00
Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed in 3.23.0a...
CVE-2026-35407
- EPSS 0.29%
- Veröffentlicht 08.04.2026 17:24:39
- Zuletzt bearbeitet 24.07.2026 21:10:00
Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found in the account email change workflow, the confirmation flow did not verify that the email change confi...
CVE-2026-35401
- EPSS 0.27%
- Veröffentlicht 08.04.2026 17:22:10
- Zuletzt bearbeitet 24.07.2026 21:10:00
Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in a single API call using aliases or chaining multiple mutations, resulting in resource ...
CVE-2026-33756
- EPSS 0.44%
- Veröffentlicht 08.04.2026 17:07:57
- Zuletzt bearbeitet 24.07.2026 22:10:00
Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multiple GraphQL operations in a single HTTP request as a JSON array but wasn't enforcing any upper limit on...
CVE-2026-24136
- EPSS 0.36%
- Veröffentlicht 23.01.2026 23:38:31
- Zuletzt bearbeitet 12.02.2026 16:15:00
Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct Object Reference (IDOR) vulnerability that allows unauthenticated actors to extract sensitive inform...
CVE-2026-23499
- EPSS 0.23%
- Veröffentlicht 21.01.2026 21:36:19
- Zuletzt bearbeitet 29.01.2026 18:19:14
Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff users or Apps to upload arbitrary files, including malicious HTML and SVG files containing Javascript...
CVE-2026-22849
- EPSS 0.21%
- Veröffentlicht 21.01.2026 21:31:14
- Zuletzt bearbeitet 29.01.2026 18:17:46
Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor was allowing users to modify rich text fields with HTML without running any backend HTML cleaners thus allowing malicious actors ...
CVE-2025-58442
- EPSS 0.31%
- Veröffentlicht 09.09.2025 19:46:45
- Zuletzt bearbeitet 15.04.2026 00:35:42
Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in the response of `accountRegister` may result in errors that could unintentionally reveal whether a user with the provided email al...