Known Vulnerabilities for Vendure by Vendurehq
Listed below are 5 of the newest known vulnerabilities associated with "Vendure" by "Vendurehq".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-67347 json | Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-location... | Not Provided | 2026-07-30 | 2026-07-30 |
| CVE-2026-63472 json | Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in ... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-63461 json | Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and facets q... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-63460 json | Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated c... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-63459 json | Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/c... | Not Provided | 2026-09-17 | 2026-09-17 |