spree
Open Source eCommerce Platform for B2B, Marketplace, and Enterprise. REST API, TypeScript SDK, and production-ready Next.js storefront. Self-host it. Own your stack. No vendor lock-in. Zero platform fees.
Activity
- Latest release
- 1mo ago
- Total releases
- 442
- Cadence
- ~2 days
- Last 12 months
- 68
Reach
- Stars
- 15.7k
Details
- License
- BSD-3-Clause
- First release
- Feb 26, 2008
| Version | Released | |
|---|---|---|
5.6.1
patch
| ||
5.6.0
minor
| ||
5.6.0.rc6
pre
| ||
5.6.0.rc5
pre
| ||
5.5.4
patch
| ||
5.6.0.rc4
pre
| ||
5.4.4
patch
| ||
5.6.0.rc3
pre
| ||
5.6.0.rc2
pre
| ||
5.6.0.rc1
pre
| ||
5.5.3
patch
| ||
5.5.2
patch
| ||
5.5.1
patch
| ||
5.5.0.rc3
pre
| ||
5.5.0
minor
| ||
5.5.0.rc2
pre
| ||
5.5.0.rc1
pre
| ||
5.3.6
patch
| ||
5.2.8
patch
| ||
5.4.3
patch
| ||
5.4.2
patch
1 CVE
GHSA-xf4v-w5x5-pv79
Jun 04, 2026
Spree: CSV Formula Injection in Customer Export
Medium
Network
Low
Low
SummaryCSV formula injection (also known as formula injection or CSV injection) affects customer export. User-controlled values customer names, email addresses, and shipping addresses. When an administrator opens a crafted Export in Microsoft Excel or LibreOffice Calc, formulas embedded in user data execute in the context of the administrator's desktop, potentially exfiltrating data or executing OS commands via DDE (Dynamic Data Exchange). DetailsAffected presenters and fields| Presenter | Path | User-controlled fields |
|---|---|---|
| Vulnerable code —
| ||
5.4.1
patch
1 CVE
GHSA-xf4v-w5x5-pv79
Jun 04, 2026
Spree: CSV Formula Injection in Customer Export
Medium
Network
Low
Low
SummaryCSV formula injection (also known as formula injection or CSV injection) affects customer export. User-controlled values customer names, email addresses, and shipping addresses. When an administrator opens a crafted Export in Microsoft Excel or LibreOffice Calc, formulas embedded in user data execute in the context of the administrator's desktop, potentially exfiltrating data or executing OS commands via DDE (Dynamic Data Exchange). DetailsAffected presenters and fields| Presenter | Path | User-controlled fields |
|---|---|---|
| Vulnerable code —
| ||
5.4.0
minor
1 CVE
GHSA-xf4v-w5x5-pv79
Jun 04, 2026
Spree: CSV Formula Injection in Customer Export
Medium
Network
Low
Low
SummaryCSV formula injection (also known as formula injection or CSV injection) affects customer export. User-controlled values customer names, email addresses, and shipping addresses. When an administrator opens a crafted Export in Microsoft Excel or LibreOffice Calc, formulas embedded in user data execute in the context of the administrator's desktop, potentially exfiltrating data or executing OS commands via DDE (Dynamic Data Exchange). DetailsAffected presenters and fields| Presenter | Path | User-controlled fields |
|---|---|---|
| Vulnerable code —
| ||
5.4.0.rc8
pre
| ||
5.4.0.rc7
pre
| ||
5.4.0.rc6
pre
| ||
5.4.0.rc5
pre
| ||
5.4.0.rc4.1
pre
| ||
5.4.0.rc4
pre
| ||
5.4.0.rc3
pre
| ||
5.4.0.rc2
pre
| ||
5.4.0.rc1
pre
| ||
5.4.0.beta10
pre
| ||
5.4.0.beta9
pre
| ||
5.4.0.beta8
pre
| ||
5.4.0.beta7
pre
| ||
5.3.5
patch
1 CVE
GHSA-xf4v-w5x5-pv79
Jun 04, 2026
Spree: CSV Formula Injection in Customer Export
Medium
Network
Low
Low
SummaryCSV formula injection (also known as formula injection or CSV injection) affects customer export. User-controlled values customer names, email addresses, and shipping addresses. When an administrator opens a crafted Export in Microsoft Excel or LibreOffice Calc, formulas embedded in user data execute in the context of the administrator's desktop, potentially exfiltrating data or executing OS commands via DDE (Dynamic Data Exchange). DetailsAffected presenters and fields| Presenter | Path | User-controlled fields |
|---|---|---|
| Vulnerable code —
| ||
5.4.0.beta6
pre
| ||
5.4.0.beta5
pre
| ||
5.4.0.beta4
pre
| ||
5.4.0.beta3
pre
| ||
5.4.0.beta2
pre
| ||
5.4.0.beta
pre
| ||
5.3.4
patch
1 CVE
GHSA-xf4v-w5x5-pv79
Jun 04, 2026
Spree: CSV Formula Injection in Customer Export
Medium
Network
Low
Low
SummaryCSV formula injection (also known as formula injection or CSV injection) affects customer export. User-controlled values customer names, email addresses, and shipping addresses. When an administrator opens a crafted Export in Microsoft Excel or LibreOffice Calc, formulas embedded in user data execute in the context of the administrator's desktop, potentially exfiltrating data or executing OS commands via DDE (Dynamic Data Exchange). DetailsAffected presenters and fields| Presenter | Path | User-controlled fields |
|---|---|---|
| Vulnerable code —
| ||
5.3.3
patch
1 CVE
GHSA-xf4v-w5x5-pv79
Jun 04, 2026
Spree: CSV Formula Injection in Customer Export
Medium
Network
Low
Low
SummaryCSV formula injection (also known as formula injection or CSV injection) affects customer export. User-controlled values customer names, email addresses, and shipping addresses. When an administrator opens a crafted Export in Microsoft Excel or LibreOffice Calc, formulas embedded in user data execute in the context of the administrator's desktop, potentially exfiltrating data or executing OS commands via DDE (Dynamic Data Exchange). DetailsAffected presenters and fields| Presenter | Path | User-controlled fields |
|---|---|---|
| Vulnerable code —
| ||
5.2.7
patch
1 CVE
GHSA-xf4v-w5x5-pv79
Jun 04, 2026
Spree: CSV Formula Injection in Customer Export
Medium
Network
Low
Low
SummaryCSV formula injection (also known as formula injection or CSV injection) affects customer export. User-controlled values customer names, email addresses, and shipping addresses. When an administrator opens a crafted Export in Microsoft Excel or LibreOffice Calc, formulas embedded in user data execute in the context of the administrator's desktop, potentially exfiltrating data or executing OS commands via DDE (Dynamic Data Exchange). DetailsAffected presenters and fields| Presenter | Path | User-controlled fields |
|---|---|---|
| Vulnerable code —
| ||
5.3.2
patch
1 CVE
GHSA-xf4v-w5x5-pv79
Jun 04, 2026
Spree: CSV Formula Injection in Customer Export
Medium
Network
Low
Low
SummaryCSV formula injection (also known as formula injection or CSV injection) affects customer export. User-controlled values customer names, email addresses, and shipping addresses. When an administrator opens a crafted Export in Microsoft Excel or LibreOffice Calc, formulas embedded in user data execute in the context of the administrator's desktop, potentially exfiltrating data or executing OS commands via DDE (Dynamic Data Exchange). DetailsAffected presenters and fields| Presenter | Path | User-controlled fields |
|---|---|---|
| Vulnerable code —
| ||
5.1.10
patch
| ||
4.10.3
patch
| ||
5.0.8
patch
|