Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Saleor — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in Saleor, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data specifically for Saleor, a headless e-commerce platform, categorized by common weakness types. It collects known security defects affecting the software, including authentication flaws, injection risks, and access control issues, covering advisories published from the product's initial release through the present. Readers can track the vendor's security advisories, analyze the distribution of specific weakness classes, and review the complete vulnerability history for the Saleor product line. The collection serves as a centralized reference for developers and security teams seeking to understand the historical security posture of the platform, enabling them to identify recurring risk patterns and assess remediation priorities.

Vendor: Saleor

CVE ID Title CVSS Severity Published
CVE-2026-93650 Saleor throttling.py get_client_ip excessive authentication CWE-307 3.7 Low 2026-09-18
CVE-2026-44472 Saleor: Account pre-hijacking vulnerability due to unverified anonymous order merge CWE-287 8.1 High 2026-08-18
CVE-2026-48744 Saleor: Anonymous users can modify channel settings via `channelUpdate` due to `all([])` bypass in permission check CWE-285 6.5 Medium 2026-08-18
CVE-2026-39851 Saleor has a user enumeration vulnerability due to different error messages CWE-204 5.3AI Medium AI 2026-04-08
CVE-2026-35407 Saleor has Cross-Account Email Change via Unbound Confirmation Token CWE-285 5.3AI Medium AI 2026-04-08
CVE-2026-35401 Saleor has a resource exhaustion vulnerability in GraphQL queries CWE-770 7.5 High 2026-04-08
CVE-2026-33756 Saleor Affected by Denial of Service via Unbounded GraphQL Query Batching CWE-770 7.5 High 2026-04-08
CVE-2026-24136 Saleor has an Insecure Direct Object Reference (IDOR) in GraphQL API CWE-639 7.5 - 2026-01-23
CVE-2026-23499 Saleor vulnerable to stored XSS via Unrestricted File Upload CWE-79 6.5AI Medium AI 2026-01-21
CVE-2026-22849 Saleor lacks proper HTML sanitization in rich text fields CWE-83 5.4AI Medium AI 2026-01-21
CVE-2025-58442 Saleor has user enumeration vulnerability due to different error messages CWE-204 5.3 Medium 2025-09-09
CVE-2024-31205 Saleor CSRF bypass in refreshToken mutation CWE-352 4.2 Medium 2024-04-08
CVE-2024-29888 Saleor vulnerable to customers addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method CWE-359 4.2 Medium 2024-03-27
CVE-2023-32694 Non-constant time HMAC comparison in Adyen plugin in Saleor CWE-203 4.8 Medium 2023-05-25
CVE-2023-26052 Saleor is vulnerable to unauthenticated information disclosure via Python exceptions CWE-209 3.7 Low 2023-03-02
CVE-2023-26051 Saleor is vulnerable to staff-authenticated error message information disclosure vulnerability via Python exceptions CWE-209 6.5 Medium 2023-03-02
CVE-2022-39275 Improper object type validation in saleor CWE-863 5.3 Medium 2022-10-06
CVE-2019-1010304 Mirumee Saleor 访问控制错误漏洞 5.3 - 2019-07-15

All 18 known CVE vulnerabilities affecting Saleor with full Chinese analysis, references, and POCs where available.