
CVE-2026-25757 Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed gues… https://www.cve.org/CVERecord?id=CVE-2026-25757
Post summary
The text reports CVE-2026-25757, a disclosure of a vulnerability in Spree e-commerce that lets unauthenticated users view completed guesses in versions before 5.0.8, 5.1.10, 5.2.7, and 5.3.2.
