{"schema_version":1,"title":"spree (RubyGems) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 7 vulnerabilities in spree (RubyGems): 1 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-94462, was published on 22 September 2026.","url":"https://junglewise.ai/threats/technologies/spree","json_url":"https://junglewise.ai/threats/technologies/spree.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/spree","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":7,"critical":0,"exploited":0,"last_7_days":1,"last_30_days":1,"last_90_days":1,"last_365_days":2},"latest":[{"cve":"CVE-2026-94462","cvss":7.1,"epss":0.0028,"slug":"cve-2026-94462-spree-store-api-broken-access-control-in-cart-association","title":"Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associ","severity":"high","exploited":false,"published_at":"2026-09-22T19:16:59.497+00:00","url":"https://junglewise.ai/threats/cve-2026-94462-spree-store-api-broken-access-control-in-cart-association"},{"cvss":5.2,"slug":"spree-csv-formula-injection-in-customer-export-65a76efc","title":"Spree CSV formula injection in Customer Export","severity":"medium","exploited":false,"published_at":"2026-06-04T18:46:04+00:00","url":"https://junglewise.ai/threats/spree-csv-formula-injection-in-customer-export-65a76efc"},{"cve":"CVE-2011-10026","cvss":4,"epss":0.0264,"slug":"cve-2011-10026-spree-commerce-is-vulnerable-to-rce-through-search-api","title":"Spree Commerce is vulnerable to RCE through Search API","severity":"medium","exploited":false,"published_at":"2025-08-20T18:30:21+00:00","url":"https://junglewise.ai/threats/cve-2011-10026-spree-commerce-is-vulnerable-to-rce-through-search-api"},{"cve":"CVE-2011-10019","cvss":3.1,"epss":0.0404,"slug":"cve-2011-10019-spree-has-remote-command-execution-vulnerability-in-search","title":"Spree has Remote Command Execution vulnerability in search functionality","severity":"low","exploited":false,"published_at":"2025-08-13T21:30:30+00:00","url":"https://junglewise.ai/threats/cve-2011-10019-spree-has-remote-command-execution-vulnerability-in-search"},{"cve":"CVE-2008-7310","epss":0.0123,"slug":"cve-2008-7310-spree-does-not-properly-restrict-the-use-of-a-hash-to-provide","title":"Spree does not properly restrict the use of a hash to provide values for a model's attributes","severity":"info","exploited":false,"published_at":"2022-05-17T05:31:08+00:00","url":"https://junglewise.ai/threats/cve-2008-7310-spree-does-not-properly-restrict-the-use-of-a-hash-to-provide"},{"cve":"CVE-2008-7311","epss":0.0123,"slug":"cve-2008-7311-spree-uses-a-hardcoded-hash-value","title":"Spree uses a hardcoded hash value","severity":"info","exploited":false,"published_at":"2022-05-17T05:30:58+00:00","url":"https://junglewise.ai/threats/cve-2008-7311-spree-uses-a-hardcoded-hash-value"},{"cve":"CVE-2013-1656","epss":0.0153,"slug":"cve-2013-1656-spree-improper-input-validation-vulnerability","title":"Spree Improper Input Validation vulnerability","severity":"info","exploited":false,"published_at":"2017-10-24T18:33:37+00:00","url":"https://junglewise.ai/threats/cve-2013-1656-spree-improper-input-validation-vulnerability"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"nokogiri (RubyGems)","slug":"nokogiri","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/nokogiri"},{"name":"rack (RubyGems)","slug":"rack","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/rack"},{"name":"camaleon_cms (RubyGems)","slug":"camaleon-cms","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/camaleon-cms"},{"name":"rails-html-sanitizer (RubyGems)","slug":"rails-html-sanitizer","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/rails-html-sanitizer"},{"name":"actionpack (RubyGems)","slug":"actionpack","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/actionpack"},{"name":"publify_core (RubyGems)","slug":"publify-core","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/publify-core"},{"name":"rubygems-update (RubyGems)","slug":"rubygems-update","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/rubygems-update"},{"name":"loofah (RubyGems)","slug":"loofah","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/loofah"},{"name":"fat_free_crm (RubyGems)","slug":"fat-free-crm","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/fat-free-crm"},{"name":"passenger (RubyGems)","slug":"passenger","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/passenger"},{"name":"oj (RubyGems)","slug":"oj","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/oj"},{"name":"openc3 (RubyGems)","slug":"openc3","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/openc3"}],"technology":{"hub":true,"name":"spree (RubyGems)","slug":"spree","vendor":{"name":"RubyGems","slug":"rubygems","url":"https://junglewise.ai/threats/vendors/rubygems"},"aliases":[],"homepage":"https://spreecommerce.org/","repo_url":"https://github.com/spree/spree","description":"Spree is an open-source e-commerce platform built with Ruby on Rails.","url":"https://junglewise.ai/threats/technologies/spree"},"most_severe":[{"cve":"CVE-2026-94462","cvss":7.1,"epss":0.0028,"slug":"cve-2026-94462-spree-store-api-broken-access-control-in-cart-association","title":"Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associ","severity":"high","exploited":false,"published_at":"2026-09-22T19:16:59.497+00:00","url":"https://junglewise.ai/threats/cve-2026-94462-spree-store-api-broken-access-control-in-cart-association"},{"cvss":5.2,"slug":"spree-csv-formula-injection-in-customer-export-65a76efc","title":"Spree CSV formula injection in Customer Export","severity":"medium","exploited":false,"published_at":"2026-06-04T18:46:04+00:00","url":"https://junglewise.ai/threats/spree-csv-formula-injection-in-customer-export-65a76efc"},{"cve":"CVE-2011-10026","cvss":4,"epss":0.0264,"slug":"cve-2011-10026-spree-commerce-is-vulnerable-to-rce-through-search-api","title":"Spree Commerce is vulnerable to RCE through Search API","severity":"medium","exploited":false,"published_at":"2025-08-20T18:30:21+00:00","url":"https://junglewise.ai/threats/cve-2011-10026-spree-commerce-is-vulnerable-to-rce-through-search-api"},{"cve":"CVE-2011-10019","cvss":3.1,"epss":0.0404,"slug":"cve-2011-10019-spree-has-remote-command-execution-vulnerability-in-search","title":"Spree has Remote Command Execution vulnerability in search functionality","severity":"low","exploited":false,"published_at":"2025-08-13T21:30:30+00:00","url":"https://junglewise.ai/threats/cve-2011-10019-spree-has-remote-command-execution-vulnerability-in-search"},{"cve":"CVE-2013-1656","epss":0.0153,"slug":"cve-2013-1656-spree-improper-input-validation-vulnerability","title":"Spree Improper Input Validation vulnerability","severity":"info","exploited":false,"published_at":"2017-10-24T18:33:37+00:00","url":"https://junglewise.ai/threats/cve-2013-1656-spree-improper-input-validation-vulnerability"},{"cve":"CVE-2008-7310","epss":0.0123,"slug":"cve-2008-7310-spree-does-not-properly-restrict-the-use-of-a-hash-to-provide","title":"Spree does not properly restrict the use of a hash to provide values for a model's attributes","severity":"info","exploited":false,"published_at":"2022-05-17T05:31:08+00:00","url":"https://junglewise.ai/threats/cve-2008-7310-spree-does-not-properly-restrict-the-use-of-a-hash-to-provide"},{"cve":"CVE-2008-7311","epss":0.0123,"slug":"cve-2008-7311-spree-uses-a-hardcoded-hash-value","title":"Spree uses a hardcoded hash value","severity":"info","exploited":false,"published_at":"2022-05-17T05:30:58+00:00","url":"https://junglewise.ai/threats/cve-2008-7311-spree-uses-a-hardcoded-hash-value"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}