MEDIUMRubyGems
GHSA-7h48-m3rw-vr27· CVE-2008-7310Spree does not properly restrict the use of a hash to provide values for a model's attributes
Modified: 12/7/2024
package
pkg:rubygems/spree
Spree does not properly restrict the use of a hash to provide values for a model's attributes
Modified: 12/7/2024
Spree has Remote Command Execution vulnerability in search functionality
Modified: 6/9/2026
Ensure that doorkeeper_token is valid when authenticating requests in API v2 calls
Modified: 7/8/2026
Spree uses a hardcoded hash value
Modified: 12/7/2024
Spree allows remote attackers to obtain sensitive information
Modified: 12/5/2024
Spree Improper Input Validation vulnerability
Modified: 12/5/2024
Spree Commerce is vulnerable to RCE through Search API
Modified: 12/1/2025
Spree: CSV Formula Injection in Customer Export
Modified: 6/4/2026