Spree
Vendor:
First CVE: Nov 17, 2010 · Active for 15 years
12
Total CVEs
More Total CVEs than 90% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Spree over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2010
15 years ago
Most Recent CVE
Feb 6, 2026
169 days ago
CVE Severity & Scoring
Spree12 CVEs
67%
17%
17%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (58.3%)
Unknown5 (41.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (58.3%)
High0 (0.0%)
Unknown5 (41.7%)
User Interaction
None7 (58.3%)
Unknown5 (41.7%)
Required0 (0.0%)
Privileges Required
Low2 (16.7%)
High0 (0.0%)
None5 (41.7%)
Unknown5 (41.7%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-10019CRITICAL Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via th | Aug 13, 2025 | 9.8 | 47 | NO | YES |
CVE-2011-10026CRITICAL Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbi | Aug 20, 2025 | 9.8 | 42 | NO | YES |
CVE-2026-22589HIGH Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) | Jan 10, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-25758HIGH Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bin | Feb 6, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-22588MEDIUM Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Authenticated Insecure Direct Object Reference (IDOR) vu | Jan 8, 2026 | 6.5 | 23 | NO | NO |
CVE-2020-26223MEDIUM Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization byp | Nov 13, 2020 | 6.5 | 22 | NO | NO |
CVE-2026-25757MEDIUM Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed guest orders by Or | Feb 6, 2026 | 5.3 | 19 | NO | NO |
CVE-2010-3978MEDIUM Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attacker | Nov 17, 2010 | 5.0 | 19 | NO | NO |
CVE-2008-7310MEDIUM Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the inten | Apr 5, 2012 | 5.0 | 18 | NO | NO |
CVE-2008-7311MEDIUM The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to | Apr 5, 2012 | 5.0 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
16.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Spree
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.3.2 | 1 | 4.0 | 1.3% | 0 | 0 |
| 1.3.1 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.3.0 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.2.4 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.2.3 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.2.2 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.2.1 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.2.0 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.1.6 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.1.5 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.1.4 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.1.3 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.1.2 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.1.1 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.1.0 | 2 | 4.2 | 1.4% | 0 | 0 |
| 1.0.7 | 1 | 4.3 | 1.5% | 0 | 0 |
| 1.0.6 | 1 | 4.3 | 1.5% | 0 | 0 |
| 1.0.5 | 1 | 4.3 | 1.5% | 0 | 0 |
| 1.0.4 | 1 | 4.3 | 1.5% | 0 | 0 |
| 1.0.3 | 1 | 4.3 | 1.5% | 0 | 0 |