vendurehq has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 8.1 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Weakness classes
Products
- vendure 4
Worst active — by depth score
CVE-2026-63472Critical· 9.1Vendure is an open-source headless commerce platform62CVE-2026-63459High· 8.7Vendure is an open-source headless commerce platform60CVE-2026-63460High· 7.5Vendure is an open-source headless commerce platform53CVE-2026-63461Medium· 5.3Vendure is an open-source headless commerce platform29
vendurehq vulnerabilities
CVEs affecting vendurehq, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-63472Critical· 9.1PoCVendure is an open-source headless commerce platform
Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing…
CVE-2026-63461Medium· 5.3Vendure is an open-source headless commerce platform
Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and facets queries combine mandatory visibility guards with caller-supplied filters using the caller-controlled filterOperat…
CVE-2026-63460High· 7.5PoCVendure is an open-source headless commerce platform
Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOperators.regex. packages/core/src/service…
CVE-2026-63459High· 8.7PoCVendure is an open-source headless commerce platform
Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrat…