Vulnerabilities

Last updated 1 hour ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
@vendure/core Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends High Risk 7.5 10 days ago 2 days ago
@vendure/core Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification Critical 9.1 10 days ago 10 days ago
@vendure/core Vendure: Shop API list queries can return non-public entities when filterOperator is OR Medium Risk 5.3 10 days ago 10 days ago
@vendure/core @vendure/core has a SQL Injection vulnerability Critical 9.1 5 months ago 4 months ago
@vendure/core Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy Low Risk 3.0 8 months ago 7 months ago
@vendure/core @vendure/core's insecure currencyCode handling allows wrong payment amounts Medium Risk 5.3 2 years ago 2 years ago
@vendure/core Vendure Cross Site Request Forgery vulnerability impacting all API requests Low Risk 3.0 3 years ago 3 years ago