Vulnerabilities (CVE)

Filtered by vendor Spryker Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-27568 1 Spryker 1 Commerce Os 2024-02-28 N/A 8.8 HIGH
SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderSearchForm[searchText]=
CVE-2022-28888 1 Spryker 1 Cloud Commerce 2024-02-28 7.5 HIGH 9.8 CRITICAL
Spryker Commerce OS 1.4.2 allows Remote Command Execution.