CVE-2019-13594High· 8.8▾ TwilightMirumee Saleor CSRF Protection Disabled
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
0.6% → 0.7%
In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.
saleor >= 2.7.0, < 2.8.0Upgrade to a patched release:
saleor 2.8.0Connected by shared product, vendor, weakness, or advisory.
CVE-2020-7964Medium· 5.3Missing Authentication for Critical Function in Saleor
CVE-2023-26051Medium· 6.5Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions
CVE-2024-29888Medium· 4.2Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method
CVE-2022-0932Medium· 6.5saleor Missing Authorization vulnerability
CVE-2023-26052Low· 3.7Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions
CVE-2026-93650Low· 3.7A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14