spree_storefront is vulnerable to Cross-Site Scripting (XSS)
64
Medium Risk
The default spree_storefront theme renders product.storefront_description through the raw helper in product description and details templates. An attacker who can edit product HTML through the admin editor source view or the API can inject <script> tags or event handlers into descriptions. The injected markup executes in the browser of every visitor who views the affected product page. The fix replaces raw with sanitize, stripping dangerous tags while preserving safe formatting HTML.
You are affected if you are using a version that falls within the vulnerable range.
spree_storefront is vulnerable to Cross-Site Scripting (XSS) in versions 5.4.0 - 5.4.1.
Upgrade the spree_storefront library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant