Vendor
high
advisory
Stored XSS in Vendure Admin Dashboard via Unsafe HTML Stripping
2 TTPs 1 CVEA stored Cross-Site Scripting (XSS) vulnerability in the Vendure Admin Dashboard allows authenticated administrators to execute arbitrary JavaScript in the context of other users viewing entity lists, leading to potential account takeover.
Vendure Dashboard
xss
web-vulnerability
dashboard
ecommerce
2t
1c
critical
advisory
Account Takeover Vulnerability in Vendure External Authentication
2 TTPs 1 CVEVendure is vulnerable to account takeover due to the ExternalAuthenticationService allowing unverified external identity linking to existing user accounts via email matching.
Vendure
account-takeover
authentication-bypass
web-application
2t
1c
critical
advisory
Vendure Shop API Unauthenticated SQL Injection Vulnerability (CVE-2026-40887)
2 rules 1 TTP 1 CVEAn unauthenticated SQL injection vulnerability (CVE-2026-40887) exists in the Vendure Shop API affecting PostgreSQL, MySQL/MariaDB, and SQLite databases, where a user-controlled query string parameter is directly interpolated into a raw SQL expression, potentially leading to arbitrary code execution.
Vendure
sqli
cve-2026-40887
web-application
injection
2r
1t
1c