Skip to content
cyberMEDIUM2026-04-21 19:24 UTC

CVE-2026-40887 - @vendure/core has a SQL Injection vulnerability

CVE ID :CVE-2026-40887 Published : April 21, 2026, 7:24 p.m. | 41 minutes ago Description :Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop AP

ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD

Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.

GET THE SUNDAY BRIEFING →

RELATED · cyber