Spreecommerce maintains a specialized e-commerce platform and related authentication modules that, while narrowly focused, occupy a prominent niche in the vulnerability landscape. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure concentrates in authorization bypasses, CSRF flaws, improper access controls, and code-injection weaknesses that are characteristic of web application frameworks handling user input and session management. Defenders should treat Spreecommerce advisories as a priority for any deployed storefronts; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spreecommerce over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-10019CRITICAL Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via th | Aug 13, 2025 | 9.8 | 47 | NO | YES |
CVE-2011-10026CRITICAL Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbi | Aug 20, 2025 | 9.8 | 42 | NO | YES |
CVE-2021-41275HIGH spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by using an underlying Devise authe | Nov 17, 2021 | 8.8 | 27 | NO | NO |
CVE-2026-22589HIGH Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) | Jan 10, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-25758HIGH Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bin | Feb 6, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-22588MEDIUM Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Authenticated Insecure Direct Object Reference (IDOR) vu | Jan 8, 2026 | 6.5 | 23 | NO | NO |
CVE-2020-26223MEDIUM Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization byp | Nov 13, 2020 | 6.5 | 22 | NO | NO |
CVE-2026-25757MEDIUM Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed guest orders by Or | Feb 6, 2026 | 5.3 | 19 | NO | NO |
CVE-2010-3978MEDIUM Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attacker | Nov 17, 2010 | 5.0 | 19 | NO | NO |
CVE-2008-7310MEDIUM Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the inten | Apr 5, 2012 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spreecommerce.
Media articles that mention a CVE ID that affects a product developed by Spreecommerce — matched by CVE ID, not by vendor name.