Information Disclosure in Spree E-commerce Solution by Spree Commerce
CVE-2026-25757
7.7HIGH
What is CVE-2026-25757?
Spree, an open-source e-commerce platform built with Ruby on Rails, is susceptible to an information disclosure vulnerability. Unauthenticated users can exploit this flaw to view completed guest orders using the Order ID. This breach may result in exposure of Personally Identifiable Information (PII) of guest users, including sensitive data such as names, addresses, and phone numbers. To remediate this issue, users are encouraged to upgrade to the patched versions: 5.0.8, 5.1.10, 5.2.7, or 5.3.2.
Affected Version(s)
spree < 5.0.8 < 5.0.8
spree >= 5.1.0, < 5.1.10 < 5.1.0, 5.1.10
spree >= 5.2.0, < 5.2.7 < 5.2.0, 5.2.7
