Divante's vulnerability footprint centers on its Vue Storefront API product, a headless e-commerce platform component that decouples storefront logic from backend commerce systems. The observed weakness involves sensitive information disclosure through error messages, a common pattern in web-facing API surfaces where verbose error handling can leak implementation details to unauthenticated consumers. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Divante over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11883MEDIUM In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the err | Apr 17, 2020 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Divante.
Media articles that mention a CVE ID that affects a product developed by Divante — matched by CVE ID, not by vendor name.