Saleor

Saleor

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 23.01.2026 23:38:31
  • Zuletzt bearbeitet 12.02.2026 16:15:00

Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct Object Reference (IDOR) vulnerability that allows unauthenticated actors to extract sensitive inform...

  • EPSS 0.04%
  • Veröffentlicht 21.01.2026 21:36:19
  • Zuletzt bearbeitet 29.01.2026 18:19:14

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff users or Apps to upload arbitrary files, including malicious HTML and SVG files containing Javascript...

  • EPSS 0.04%
  • Veröffentlicht 21.01.2026 21:31:14
  • Zuletzt bearbeitet 29.01.2026 18:17:46

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor was allowing users to modify rich text fields with HTML without running any backend HTML cleaners thus allowing malicious actors ...

  • EPSS 0.04%
  • Veröffentlicht 09.09.2025 19:46:45
  • Zuletzt bearbeitet 11.09.2025 17:14:25

Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in the response of `accountRegister` may result in errors that could unintentionally reveal whether a user with the provided email al...

  • EPSS 0.08%
  • Veröffentlicht 08.04.2024 15:15:08
  • Zuletzt bearbeitet 07.01.2026 20:05:30

Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19, an attacker may bypass cross-set request forgery (CSRF) validation when calling refresh token mutation with e...

  • EPSS 0.42%
  • Veröffentlicht 27.03.2024 19:15:49
  • Zuletzt bearbeitet 08.01.2026 19:00:21

Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its...

  • EPSS 0.29%
  • Veröffentlicht 25.05.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 08:03:52

Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing attacks. Malicious users could abuse this vulnerability on Saleor deployments having the Adyen plugin enabled in order to determin...

  • EPSS 0.43%
  • Veröffentlicht 02.03.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:50:39

Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive information l...

  • EPSS 0.28%
  • Veröffentlicht 02.03.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:50:39

Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive information l...

  • EPSS 0.32%
  • Veröffentlicht 06.10.2022 18:16:17
  • Zuletzt bearbeitet 21.11.2024 07:17:56

Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking the ID type input which allowed to access database objects that the authenticated user may not be allowed to access. This vulnerab...