Vulnerabilities
Last updated 1 hour ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends | High Risk 7.5 | 10 days ago | 2 days ago |
|
|
Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification | Critical 9.1 | 10 days ago | 10 days ago |
|
|
Vendure: Shop API list queries can return non-public entities when filterOperator is OR | Medium Risk 5.3 | 10 days ago | 10 days ago |
|
|
@vendure/core has a SQL Injection vulnerability | Critical 9.1 | 5 months ago | 4 months ago |
|
|
Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy | Low Risk 3.0 | 8 months ago | 7 months ago |
|
|
@vendure/core's insecure currencyCode handling allows wrong payment amounts | Medium Risk 5.3 | 2 years ago | 2 years ago |
|
|
Vendure Cross Site Request Forgery vulnerability impacting all API requests | Low Risk 3.0 | 3 years ago | 3 years ago |
Page 1