Junglewise Threat Intelligence

CVE-2011-10026: Spree Commerce is vulnerable to RCE through Search API

CVE-2011-10026 · Severity: medium · CVSS 4 · Published 2025-08-20

Technologies: spree (RubyGems). Vendors: RubyGems.

Executive brief

Spree Commerce is vulnerable to RCE through Search API

Affected products

  • RubyGems spree
  • RubyGems rd_searchlogic

Related threats