Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Saleor — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting Saleor. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Saleor is an open-source e-commerce platform built on Django and GraphQL, serving as a headless commerce solution for online businesses. Historically, vulnerabilities have included cross-site scripting (XSS), remote code execution (RCE), privilege escalation, and insecure direct object references (IDOR), often stemming from improper input validation and access controls. While no major public security incidents have been widely reported, the 18 CVEs on record highlight persistent security concerns, particularly around API endpoints and user permissions. The platform's modular architecture and third-party integrations introduce additional attack surfaces, requiring rigorous security hardening and regular updates to mitigate risks.

CVE ID Title CVSS Severity Published
CVE-2026-44472 Saleor: Account pre-hijacking vulnerability due to unverified anonymous order merge — saleor CWE-287 8.1 High 2026-08-18
CVE-2026-48744 Saleor: Anonymous users can modify channel settings via `channelUpdate` due to `all([])` bypass in permission check — saleor CWE-285 6.5 Medium 2026-08-18
CVE-2026-42175 requests-hardened: Server-Side Request Forgery (SSRF) in requests-hardened RFC 6598 — requests-hardened CWE-918 6.5 Medium 2026-05-12
CVE-2026-39851 Saleor has a user enumeration vulnerability due to different error messages — saleor CWE-204 5.3AI Medium AI 2026-04-08
CVE-2026-35407 Saleor has Cross-Account Email Change via Unbound Confirmation Token — saleor CWE-285 5.3AI Medium AI 2026-04-08
CVE-2026-35401 Saleor has a resource exhaustion vulnerability in GraphQL queries — saleor CWE-770 7.5 High 2026-04-08
CVE-2026-33756 Saleor Affected by Denial of Service via Unbounded GraphQL Query Batching — saleor CWE-770 7.5 High 2026-04-08
CVE-2026-24136 Saleor has an Insecure Direct Object Reference (IDOR) in GraphQL API — saleor CWE-639 7.5 - 2026-01-23
CVE-2026-23499 Saleor vulnerable to stored XSS via Unrestricted File Upload — saleor CWE-79 6.5AI Medium AI 2026-01-21
CVE-2026-22849 Saleor lacks proper HTML sanitization in rich text fields — saleor CWE-83 5.4AI Medium AI 2026-01-21
CVE-2025-58442 Saleor has user enumeration vulnerability due to different error messages — saleor CWE-204 5.3 Medium 2025-09-09
CVE-2024-31205 Saleor CSRF bypass in refreshToken mutation — saleor CWE-352 4.2 Medium 2024-04-08
CVE-2024-29888 Saleor vulnerable to customers addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method — saleor CWE-359 4.2 Medium 2024-03-27
CVE-2024-29036 Saleor Storefront session leak in cache — storefront CWE-200 4.3 Medium 2024-03-20
CVE-2023-3294 Cross-site Scripting (XSS) - DOM in saleor/react-storefront — saleor/react-storefront CWE-79 6.1 - 2023-06-16
CVE-2023-32694 Non-constant time HMAC comparison in Adyen plugin in Saleor — saleor CWE-203 4.8 Medium 2023-05-25
CVE-2023-26052 Saleor is vulnerable to unauthenticated information disclosure via Python exceptions — saleor CWE-209 3.7 Low 2023-03-02
CVE-2023-26051 Saleor is vulnerable to staff-authenticated error message information disclosure vulnerability via Python exceptions — saleor CWE-209 6.5 Medium 2023-03-02
CVE-2022-39275 Improper object type validation in saleor — saleor CWE-863 5.3 Medium 2022-10-06
CVE-2022-0932 Missing Authorization in saleor/saleor — saleor/saleor CWE-862 7.1 - 2022-03-11
CVE-2019-1010304 Mirumee Saleor 访问控制错误漏洞 — Saleor 5.3 - 2019-07-15

This page lists every published CVE security advisory associated with Saleor. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.