📦 Spree

by Spreecommerce

🔍 What is Spree?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25758

HIGH CVSS 7.5 Feb 6, 2026

A critical IDOR vulnerability in Spree Commerce allows guest users to manipulate address ID parameters during checkout, bypassing ownership validation. This enables unauthorized access to other guests...

CVE-2026-25757

MEDIUM CVSS 5.3 Feb 6, 2026

Unauthenticated users can view completed guest orders by Order ID in Spree e-commerce platform, potentially exposing guest user PII including names, addresses, and phone numbers. This affects all Spre...