OroCommerce - an open-source Business to Business Commerce application. \nThis package contains bundles and needs to be added as a dependency in an OroCommerce application.
88%
Total Score
88
100
100
There were no new or closed issues and no merged pull requests in the last month, which is a modest process-activity concern, though 95 recent commits and 25 active maintainers provide compensating evidence.
| Title | Versions | Severity |
|---|---|---|
CVE-2023-32065 oro/commerce is vulnerable to Improper Access Control in versions 4.2.0 - 4.2.10, 5.0.0 - 5.0.11 and 5.1.0 - 5.1.1. | 4.2.0 - 4.2.105.0.0 - 5.0.115.1.0 - 5.1.1 | Medium |
CVE-2022-35950 oro/commerce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.1.0 - 4.1.13, 4.2.0 - 4.2.10, 5.0.0 - 5.0.11 and 5.1.0 - 5.1.1. | 4.1.0 - 4.1.134.2.0 - 4.2.105.0.0 - 5.0.11 +1 more | Medium |
CVE-2022-31037 oro/commerce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.1.0 - 5.0.6. | 4.1.0 - 5.0.6 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
oro/platform Version 7.0.* | — | — |
oro/marketing Version 7.0.* | — | — |
oroinc/soap-client Version ^0.2.7 | — | — |
oro/calendar-bundle Version 7.0.* | — | — |
oro/customer-portal Version 7.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.