Saleor is a modestly represented open-source e-commerce platform and headless storefront framework deployed across online retail and marketplace applications. Its vulnerability profile centers on the core platform and React-based storefront components, with a durable pattern of web-application weaknesses including cross-site scripting, CSRF, authorization bypass, resource exhaustion, and sensitive-data exposure in error handling—issues characteristic of full-stack web applications managing payment and user account data. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Saleor over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35401HIGH Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in a single API cal | Apr 8, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-33756HIGH Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multiple GraphQL operations in a singl | Apr 8, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-24136HIGH Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct Object Reference (IDOR) vulner | Jan 24, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-35407MEDIUM Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found in the account email change work | Apr 8, 2026 | 6.5 | 25 | NO | NO |
CVE-2026-23499MEDIUM Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff users or Apps to upload arbitra | Jan 21, 2026 | 5.4 | 23 | NO | NO |
CVE-2026-22849MEDIUM Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor was allowing users to modify rich text fields with HTML wit | Jan 21, 2026 | 4.8 | 22 | NO | NO |
CVE-2022-0932MEDIUM Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2. | Mar 11, 2022 | 6.5 | 22 | NO | NO |
CVE-2026-39851MEDIUM Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided ema | Apr 8, 2026 | 4.3 | 20 | NO | NO |
CVE-2024-29036MEDIUM Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymou | Mar 20, 2024 | 6.5 | 20 | NO | NO |
CVE-2023-3294MEDIUM Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7. | Jun 16, 2023 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Saleor.
Media articles that mention a CVE ID that affects a product developed by Saleor — matched by CVE ID, not by vendor name.