Commerceguys operates a narrowly scoped e-commerce platform portfolio centered on its Commerce and Commerce Reorder products, with its observed vulnerability profile reflecting web application security challenges. The recurring weakness classes—cross-site request forgery, cross-site scripting, and sensitive information exposure—are characteristic of input-handling and session-management issues common in web-facing commerce platforms where user interaction and data sensitivity intersect. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Commerceguys over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2116MEDIUM Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for | Aug 31, 2012 | 6.8 | 20 | NO | NO |
CVE-2014-9025MEDIUM The default checkout completion rule in the commerce_order module in the Drupal Commerce module 7.x-1.x before 7.x-1.10 for Drupal uses the email address as the username for new ac | Nov 20, 2014 | 5.0 | 15 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to i | Oct 1, 2012 | 3.5 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Commerceguys.
Media articles that mention a CVE ID that affects a product developed by Commerceguys — matched by CVE ID, not by vendor name.