SprykerCVEs & Vulnerabilities
2 CVEs affecting Spryker products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
cloud commerce 1commerce os 1
CVE-2023-27568HIGH
SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderSearchForm[searchText]=
4 May 2023
8.8
CVSS
CVE-2022-28888CRITICAL
Spryker Commerce OS 1.4.2 allows Remote Command Execution.
13 Jul 2022
9.8
CVSS
← PrevPage 1 / 1Next →