Nebulab develops the Solidus e-commerce platform and related authentication libraries, with a focused vulnerability footprint centered on web-application-layer weaknesses including cross-site request forgery, improper input validation, regular expression denial of service, and missing authorization controls. These recurring patterns reflect the authentication and request-handling demands of web-based shopping systems; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nebulab over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41274HIGH solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devise is subject to a CSRF vulnera | Nov 17, 2021 | 8.8 | 29 | NO | NO |
CVE-2021-43805HIGH Solidus is a free, open-source ecommerce platform built on Rails. Versions of Solidus prior to 3.1.4, 3.0.4, and 2.11.13 have a denial of service vulnerability that could be exploi | Dec 7, 2021 | 7.5 | 25 | NO | NO |
CVE-2022-31000MEDIUM solidus_backend is the admin interface for the Solidus e-commerce framework. Versions prior to 3.1.6, 3.0.6, and 2.11.16 contain a cross-site request forgery (CSRF) vulnerability. | Jun 1, 2022 | 4.3 | 18 | NO | NO |
CVE-2021-43846MEDIUM `solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior to 3.1.5, 3.0.5, and 2.11.14 contain a cross-site request for | Dec 20, 2021 | 4.3 | 18 | NO | NO |
CVE-2020-15109MEDIUM In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerability allows a malicious custom | Aug 4, 2020 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nebulab.
Media articles that mention a CVE ID that affects a product developed by Nebulab — matched by CVE ID, not by vendor name.