CVE-2022-0932Medium· 6.5▾ Sunlitsaleor Missing Authorization vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
1.0% → 1.0%
Missing Authorization in saleor prior to 3.1.2.
saleor < 3.1.2Upgrade to a patched release:
saleor 3.1.2Connected by shared product, vendor, weakness, or advisory.
CVE-2023-26051Medium· 6.5Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions
CVE-2024-29888Medium· 4.2Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method
CVE-2023-26052Low· 3.7Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions
CVE-2020-7964Medium· 5.3Missing Authentication for Critical Function in Saleor
CVE-2019-13594High· 8.8Mirumee Saleor CSRF Protection Disabled
CVE-2026-93650Low· 3.7A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14