Storefront
This hub aggregates every CVE we track for Storefront, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
1
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2MEDIUM2CRITICAL1
Monthly trend
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-082026-07
Latest CVEs
The 5 most recently published vulnerabilities affecting Storefront.
- CVE-2025-26206Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component9.0
- CVE-2024-29036Saleor Storefront session leak in cache4.3
- CVE-2022-27503Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU96.1
- CVE-2008-1341SQL injection vulnerability in SearchResults.aspx in LaGarde StoreFront 6 before SP8 allows remote attackers to execute arbitrary SQL commands via the CategoryId parameter. NOTE: the provenance of...7.5
- CVE-2003-0557SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.7.5
Product normalization is registry-driven with AI assist and human review. How it works