oro/commerce
Main OroCommerce package with core functionality.
Activity
- Latest release
- Jun 11, 2026
- Total releases
- 219
- Cadence
- ~19 days
- Last 12 months
- 13
Reach
- Stars
- 206
Details
- License
- unknown
- First release
- Sep 28, 2015
| Version | Released | |
|---|---|---|
6.1.10
patch
| ||
7.0.3
patch
| ||
7.0.2
patch
| ||
7.0.1
patch
| ||
6.1.9
patch
| ||
7.0.0
major
| ||
6.1.8
patch
| ||
7.0.0-rc
pre
| ||
6.1.7
patch
| ||
6.0.10
patch
| ||
6.1.6
patch
| ||
6.1.5
patch
| ||
6.1.5-rc1
pre
| ||
6.1.4
patch
| ||
6.1.3
patch
| ||
6.0.9
patch
| ||
6.1.2
patch
| ||
6.1.1
patch
| ||
6.1.0
minor
| ||
6.0.8
patch
| ||
6.1.0-rc.3
pre
| ||
6.1.0-rc.2
pre
| ||
6.0.7
patch
| ||
6.1.0-rc
pre
| ||
6.0.6
patch
| ||
6.0.5
patch
| ||
6.0.4
patch
| ||
6.0.3
patch
| ||
5.1.8
patch
| ||
6.0.2
patch
| ||
6.0.1
patch
| ||
5.1.7
patch
| ||
6.0.0
major
| ||
6.0.0-rc
pre
| ||
5.1.6
patch
| ||
5.1.5
patch
| ||
6.0.0-beta.1
pre
| ||
5.1.4
patch
| ||
5.1.3
patch
| ||
5.1.2
patch
| ||
5.1.1
patch
| ||
5.0.11
patch
| ||
5.1.0
minor
2 CVEs
CVE-2023-32065
GHSA-88g2-xgh9-4ph2
Nov 27, 2023
OroCommerce get-totals-for-checkout API endpoint returns unwanted data
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
Detailed Checkout totals information may be received by Checkout ID Affected versions
4.2.0
4.2.1
4.2.10
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
4.2.9
5.0.0
+ 11 more Show less
5.0.1
5.0.10
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
Fixed in
5.0.11
5.1.1
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-35950
GHSA-2jc6-3fhj-8q84
Oct 10, 2023
OroCommerce Cross-site Scripting vulnerability in add note dialog of Shopping List line item
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
ImpactThe JS payload added to the product name may be executed at the storefront when adding a note to the shopping list line item containing a vulnerable product. An attacker should be able to edit a product in the admin area and force a user to add this product to Shopping List and click add a note for it. Affected versions
4.1.0
4.1.1
4.1.1-rc
4.1.1-rc2
4.1.10
4.1.11
4.1.12
4.1.13
4.1.2
4.1.3
4.1.4
4.1.5
+ 27 more Show less
4.1.6
4.1.7
4.1.8
4.1.9
4.2.0
4.2.1
4.2.10
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
4.2.9
5.0.0
5.0.1
5.0.10
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
Fixed in
5.0.11
5.1.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
5.0.10
patch
2 CVEs
CVE-2023-32065
GHSA-88g2-xgh9-4ph2
Nov 27, 2023
OroCommerce get-totals-for-checkout API endpoint returns unwanted data
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
Detailed Checkout totals information may be received by Checkout ID Affected versions
4.2.0
4.2.1
4.2.10
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
4.2.9
5.0.0
+ 11 more Show less
5.0.1
5.0.10
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
Fixed in
5.0.11
5.1.1
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-35950
GHSA-2jc6-3fhj-8q84
Oct 10, 2023
OroCommerce Cross-site Scripting vulnerability in add note dialog of Shopping List line item
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
ImpactThe JS payload added to the product name may be executed at the storefront when adding a note to the shopping list line item containing a vulnerable product. An attacker should be able to edit a product in the admin area and force a user to add this product to Shopping List and click add a note for it. Affected versions
4.1.0
4.1.1
4.1.1-rc
4.1.1-rc2
4.1.10
4.1.11
4.1.12
4.1.13
4.1.2
4.1.3
4.1.4
4.1.5
+ 27 more Show less
4.1.6
4.1.7
4.1.8
4.1.9
4.2.0
4.2.1
4.2.10
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
4.2.9
5.0.0
5.0.1
5.0.10
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
Fixed in
5.0.11
5.1.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
5.1.0-rc.2
pre
| ||
5.0.9
patch
2 CVEs
CVE-2023-32065
GHSA-88g2-xgh9-4ph2
Nov 27, 2023
OroCommerce get-totals-for-checkout API endpoint returns unwanted data
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
Detailed Checkout totals information may be received by Checkout ID Affected versions
4.2.0
4.2.1
4.2.10
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
4.2.9
5.0.0
+ 11 more Show less
5.0.1
5.0.10
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
Fixed in
5.0.11
5.1.1
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-35950
GHSA-2jc6-3fhj-8q84
Oct 10, 2023
OroCommerce Cross-site Scripting vulnerability in add note dialog of Shopping List line item
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
ImpactThe JS payload added to the product name may be executed at the storefront when adding a note to the shopping list line item containing a vulnerable product. An attacker should be able to edit a product in the admin area and force a user to add this product to Shopping List and click add a note for it. Affected versions
4.1.0
4.1.1
4.1.1-rc
4.1.1-rc2
4.1.10
4.1.11
4.1.12
4.1.13
4.1.2
4.1.3
4.1.4
4.1.5
+ 27 more Show less
4.1.6
4.1.7
4.1.8
4.1.9
4.2.0
4.2.1
4.2.10
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
4.2.9
5.0.0
5.0.1
5.0.10
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
Fixed in
5.0.11
5.1.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
5.1.0-rc.1
pre
| ||
5.0.8
patch
2 CVEs
CVE-2023-32065
GHSA-88g2-xgh9-4ph2
Nov 27, 2023
OroCommerce get-totals-for-checkout API endpoint returns unwanted data
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
Detailed Checkout totals information may be received by Checkout ID Affected versions
4.2.0
4.2.1
4.2.10
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
4.2.9
5.0.0
+ 11 more Show less
5.0.1
5.0.10
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
Fixed in
5.0.11
5.1.1
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-35950
GHSA-2jc6-3fhj-8q84
Oct 10, 2023
OroCommerce Cross-site Scripting vulnerability in add note dialog of Shopping List line item
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
ImpactThe JS payload added to the product name may be executed at the storefront when adding a note to the shopping list line item containing a vulnerable product. An attacker should be able to edit a product in the admin area and force a user to add this product to Shopping List and click add a note for it. Affected versions
4.1.0
4.1.1
4.1.1-rc
4.1.1-rc2
4.1.10
4.1.11
4.1.12
4.1.13
4.1.2
4.1.3
4.1.4
4.1.5
+ 27 more Show less
4.1.6
4.1.7
4.1.8
4.1.9
4.2.0
4.2.1
4.2.10
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
4.2.9
5.0.0
5.0.1
5.0.10
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
Fixed in
5.0.11
5.1.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
5.1.0-beta.2
pre
| ||
5.1.0-beta.1
pre
|