You can find the Solidus security policy at https://solidus.io/security.
Repository navigation
Security: solidusio/solidus
Security
SECURITY.md
-
Users with UserManagement permissions can assign themselves the admin role or change an admin's passwordGHSA-rw5f-4cm4-pc4m published
Oct 7, 2026 by jarednormanHigh -
Missing authorization check on return item inventory units allows cancelling other customers' returnsGHSA-6p7r-vx57-9gw3 published
Oct 7, 2026 by jarednormanModerate -
Stored cross-site scripting in Solidus admin customer purchased itemsGHSA-g9c8-3mxq-rpgh published
Oct 7, 2026 by jarednormanHigh -
Unrestricted type assignment in admin payment methods controllerGHSA-3cfg-886h-22vf published
Oct 7, 2026 by jarednormanLow -
Checkout state skip via unvalidated state parameterGHSA-qwqm-3jx5-rr8m published
Oct 7, 2026 by jarednormanModerate -
Storefront password reset endpoint allows for account enumerationGHSA-mhwq-2v9w-r659 published
Oct 7, 2026 by jarednormanModerate -
Customers can attach another user's stored gateway payment profile to their own paymentGHSA-vgwx-9pm9-8qvj published
Oct 7, 2026 by jarednormanLow -
Stored cross-site scripting in Solidus product descriptionsGHSA-x943-j5hw-mr2w published
Oct 7, 2026 by jarednormanHigh -
Unauthenticated tampering with and disclosure of guest-checkout credit cards via nil-user abilityGHSA-92gv-2pxv-7gjg published
Sep 9, 2026 by jarednormanModerate -
Arbitrary payment amounts via the orders and payments APIs enable order underpaymentGHSA-c2fq-w6qj-3hj4 published
Sep 9, 2026 by jarednormanModerate
Learn more about advisories related to solidusio/solidus in the GitHub Advisory Database