Saleor

Saleor

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 08.04.2026 17:33:37
  • Zuletzt bearbeitet 20.04.2026 20:01:43

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed in 3.23.0a...

  • EPSS 0.03%
  • Veröffentlicht 08.04.2026 17:24:39
  • Zuletzt bearbeitet 15.04.2026 17:51:20

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found in the account email change workflow, the confirmation flow did not verify that the email change confi...

  • EPSS 0.04%
  • Veröffentlicht 08.04.2026 17:22:10
  • Zuletzt bearbeitet 20.04.2026 20:03:15

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in a single API call using aliases or chaining multiple mutations, resulting in resource ...

  • EPSS 0.08%
  • Veröffentlicht 08.04.2026 17:07:57
  • Zuletzt bearbeitet 20.04.2026 20:04:43

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multiple GraphQL operations in a single HTTP request as a JSON array but wasn't enforcing any upper limit on...

  • EPSS 0.02%
  • Veröffentlicht 23.01.2026 23:38:31
  • Zuletzt bearbeitet 12.02.2026 16:15:00

Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct Object Reference (IDOR) vulnerability that allows unauthenticated actors to extract sensitive inform...

  • EPSS 0.05%
  • Veröffentlicht 21.01.2026 21:36:19
  • Zuletzt bearbeitet 29.01.2026 18:19:14

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff users or Apps to upload arbitrary files, including malicious HTML and SVG files containing Javascript...

  • EPSS 0.05%
  • Veröffentlicht 21.01.2026 21:31:14
  • Zuletzt bearbeitet 29.01.2026 18:17:46

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor was allowing users to modify rich text fields with HTML without running any backend HTML cleaners thus allowing malicious actors ...

  • EPSS 0.05%
  • Veröffentlicht 09.09.2025 19:46:45
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in the response of `accountRegister` may result in errors that could unintentionally reveal whether a user with the provided email al...

  • EPSS 0.08%
  • Veröffentlicht 08.04.2024 15:15:08
  • Zuletzt bearbeitet 07.01.2026 20:05:30

Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19, an attacker may bypass cross-set request forgery (CSRF) validation when calling refresh token mutation with e...

  • EPSS 0.42%
  • Veröffentlicht 27.03.2024 19:15:49
  • Zuletzt bearbeitet 08.01.2026 19:00:21

Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its...