CVE-2020-7964Medium· 5.3▾ SunlitMissing Authentication for Critical Function in Saleor
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.1%
1.1% → 1.1%
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer).
saleor >= 2.0.0, < 2.9.1Upgrade to a patched release:
saleor 2.9.1Connected by shared product, vendor, weakness, or advisory.
CVE-2023-26051Medium· 6.5Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions
CVE-2024-29888Medium· 4.2Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method
CVE-2022-0932Medium· 6.5saleor Missing Authorization vulnerability
CVE-2019-13594High· 8.8Mirumee Saleor CSRF Protection Disabled
CVE-2023-26052Low· 3.7Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions
CVE-2026-93650Low· 3.7A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14