Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Spreecommerce

First CVE: Nov 17, 2010Active for: 16 yearsTotal CVEs: 13
37.3
VTI Score
Medium

Spreecommerce maintains a specialized e-commerce platform and related authentication modules that, while narrowly focused, occupy a prominent niche in the vulnerability landscape. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure concentrates in authorization bypasses, CSRF flaws, improper access controls, and code-injection weaknesses that are characteristic of web application frameworks handling user input and session management. Defenders should treat Spreecommerce advisories as a priority for any deployed storefronts; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Spreecommerce over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2010
15 years ago
Most Recent CVE
Feb 6, 2026
168 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-10019CRITICAL
Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via th
Aug 13, 20259.847NOYES
CVE-2011-10026CRITICAL
Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbi
Aug 20, 20259.842NOYES
CVE-2021-41275HIGH
spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by using an underlying Devise authe
Nov 17, 20218.827NONO
CVE-2026-22589HIGH
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR)
Jan 10, 20267.526NONO
CVE-2026-25758HIGH
Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bin
Feb 6, 20267.524NONO
CVE-2026-22588MEDIUM
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Authenticated Insecure Direct Object Reference (IDOR) vu
Jan 8, 20266.523NONO
CVE-2020-26223MEDIUM
Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization byp
Nov 13, 20206.522NONO
CVE-2026-25757MEDIUM
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed guest orders by Or
Feb 6, 20265.319NONO
CVE-2010-3978MEDIUM
Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attacker
Nov 17, 20105.019NONO
CVE-2008-7310MEDIUM
Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the inten
Apr 5, 20125.018NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
62%
23%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (61.5%)
Unknown5 (38.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (61.5%)
High0 (0.0%)
Unknown5 (38.5%)
User Interaction
None7 (53.8%)
Unknown5 (38.5%)
Required1 (7.7%)
Privileges Required
Low2 (15.4%)
High0 (0.0%)
None6 (46.2%)
Unknown5 (38.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
15.4% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Spreecommerce.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Spreecommerce — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Spreecommerce's Products

View all 3 CNAs →

Top CWEs