CPE
high
advisory
Stored XSS in Vendure Admin Dashboard via Unsafe HTML Stripping
2 TTPs 1 CVEA stored Cross-Site Scripting (XSS) vulnerability in the Vendure Admin Dashboard allows authenticated administrators to execute arbitrary JavaScript in the context of other users viewing entity lists, leading to potential account takeover.
Vendure Dashboard
xss
web-vulnerability
dashboard
ecommerce
2t
1c
critical
advisory
Account Takeover Vulnerability in Vendure External Authentication
2 TTPs 1 CVEVendure is vulnerable to account takeover due to the ExternalAuthenticationService allowing unverified external identity linking to existing user accounts via email matching.
Vendure
account-takeover
authentication-bypass
web-application
2t
1c