OroCommerce - an open-source Business to Business Commerce application. \nThis package contains bundles and needs to be added as a dependency in an OroCommerce application.
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2023-32065 oro/commerce is vulnerable to Improper Access Control in versions 4.2.0 - 4.2.10, 5.0.0 - 5.0.11 and 5.1.0 - 5.1.1. | 4.2.0 - 4.2.105.0.0 - 5.0.115.1.0 - 5.1.1 | Medium |
CVE-2022-35950 oro/commerce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.1.0 - 4.1.13, 4.2.0 - 4.2.10, 5.0.0 - 5.0.11 and 5.1.0 - 5.1.1. | 4.1.0 - 4.1.134.2.0 - 4.2.105.0.0 - 5.0.11 +1 more | Medium |
CVE-2022-31037 oro/commerce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.1.0 - 5.0.6. | 4.1.0 - 5.0.6 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
oro/platform Version 7.0.* | — | — |
oro/marketing Version 7.0.* | — | — |
oro/calendar-bundle Version 7.0.* | — | — |
oro/customer-portal Version 7.0.* | — | — |
besimple/soap-client Version ^0.2.6 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant