Vulnerabilidades en vendurehq
7 resultadosAnálisis Vexday
A VendureHQ possui 3 vulnerabilidades registradas, sendo 1 crítica e nenhuma sob exploração ativa conhecida. A fraqueza dominante (CWE-202) sugere problema em validação de informações, com 1 CVE publicado recentemente, indicando risco moderado que requer monitoramento mas sem urgência crítica no curto prazo.
CVE-2026-40887CRITICAL@vendure/core has a SQL Injection vulnerabilityEPSS 2.2%CVE-2026-63460HIGHVendure: Unauthenticated ReDoS via `regex` filter on SQLite backendsEPSS 0.6%CVE-2026-63472CRITICALVendure: External-authentication account takeover: external login linked to a pre-existing account by email without verificationEPSS 0.6%CVE-2026-67347MEDIUMVendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset UpdateEPSS 0.5%CVE-2026-63461MEDIUMVendure: Shop API list queries can return non-public entities when filterOperator is OREPSS 0.4%CVE-2026-63459HIGHVendure: Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptionsEPSS 0.4%CVE-2026-25050LOWVendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategyEPSS 0.4%