CVE-2011-10019Critical· 9.8▾ AbyssalPoC availableSpreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked …
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 1.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
5.8%
Metasploit ×1 (last check)
Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication.
spree < 0.60.2Upgrade past the affected range:
spree 0.60.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-104849Critical· 9.5Tinypool is a minimal Node.js worker thread pool implementation
CVE-2026-85625High· 8.1sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where
CVE-2026-44495High· 7.0Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-105857Critical· 10.0Payload is a free and open source headless content management system
CVE-2026-105858High· 8.1Payload is a free and open source headless content management system
CVE-2023-3519Critical· 9.8Unauthenticated remote code execution