aimeos/ai-controller-frontend
Aimeos business controller logic for frontend
Activity
- Latest release
- 3mo ago
- Total releases
- 159
- Cadence
- ~13 days
- Last 12 months
- 9
Reach
- Stars
- —
Details
- License
- unknown
- First release
- Jul 07, 2016
| Version | Released | |
|---|---|---|
2022.10.9
patch
| ||
2023.10.13
patch
| ||
2024.10.5
patch
| ||
2025.10.4
patch
| ||
2026.04.2
patch
| ||
2026.04.1
major
| ||
2025.10.3
patch
| ||
2025.10.2
patch
| ||
2025.10.1
minor
| ||
2025.07.1
minor
| ||
2024.10.4
patch
| ||
2025.04.1
major
| ||
2023.10.12
patch
| ||
2024.10.3
patch
| ||
2023.10.11
patch
| ||
2024.10.2
patch
| ||
2024.10.1
minor
| ||
2023.10.10
patch
| ||
2024.07.3
patch
| ||
2024.07.2
patch
| ||
2024.07.1
minor
| ||
2020.10.15
patch
| ||
2021.10.8
patch
| ||
2022.10.8
patch
| ||
2023.10.9
patch
| ||
2024.04.2
patch
| ||
2024.04.1
major
1 CVE
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev | ||
2023.10.8
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2023.10.7
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2023.10.6
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2023.10.5
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2023.10.4
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2023.10.3
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2023.10.2
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2023.10.1
minor
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2023.07.1
minor
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2022.10.7
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2023.04.2
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2023.04.1
major
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2022.10.6
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2022.10.5
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2022.10.4
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2022.10.3
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2022.10.2
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2021.10.7
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2022.10.1
minor
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2022.07.3
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2022.07.2
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2022.07.1
minor
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev | ||
2022.04.5
patch
2 CVEs
CVE-2024-39319
GHSA-rw3j-574h-mrcq
Sep 26, 2024
IDOR vulnerability in account profile page
Medium
Network
Low
None
None
ImpactInsecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer Affected versions
2024.04.1
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
+ 122 more Show less
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
2024.04.2
References
Updated Mar 05, 2025 · Source: OSV.dev
CVE-2024-39325
GHSA-m9gv-6p22-qgmj
Jul 05, 2024
ai-controller-frontend payment status in basket isn't reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactPayment status in basket isn't reset Affected versions
2023.04.1
2023.04.2
2023.07.1
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2022.04.1
+ 121 more Show less
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.07.1
2021.07.2
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2016.07.1
2016.07.2
2016.07.3
2016.10.1
2016.10.2
2016.10.3
2016.10.4
2016.10.5
2016.10.6
2017.01.1
2017.01.2
2017.04.1
2017.04.2
2017.04.3
2017.04.4
2017.04.5
2017.04.6
2017.04.7
2017.07.1
2017.07.2
2017.07.3
2017.10.1
2017.10.2
2017.10.3
2017.10.4
2017.10.5
2018.01.1
2018.01.2
2018.04.1
2018.04.2
2018.04.3
2018.07.1
2018.07.2
2018.07.3
2018.07.4
2018.07.5
2018.07.6
2018.10.1
2018.10.2
2018.10.3
2018.10.4
2018.10.5
2018.10.6
2018.10.7
2018.10.8
2018.10.9
2019.01.1
2019.01.2
2019.04.1
2019.04.2
2019.04.3
2019.04.4
2019.04.5
2019.07.1
2019.07.2
2019.07.3
2019.07.4
2019.07.5
2019.10.1
2019.10.10
2019.10.11
2019.10.12
2019.10.13
2019.10.14
2019.10.15
2019.10.16
2019.10.2
2019.10.3
2019.10.4
2019.10.5
2019.10.6
2019.10.7
2019.10.8
2019.10.9
2020.01.1
2020.01.2
2020.04.1
2020.07.1
2020.07.2
2020.10.1
2020.10.10
2020.10.11
2020.10.12
2020.10.13
2020.10.14
2020.10.2
2020.10.3
2020.10.4
2020.10.5
2020.10.6
2020.10.7
2020.10.8
2020.10.9
Fixed in
2020.10.15
2021.10.8
2022.10.8
2023.10.9
References
Updated Jul 05, 2024 · Source: OSV.dev |