6 Total advisories
6 Vulnerabilities
0 Malware
Dependency scanning
Check whether @vendure/core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.1
CVE-2026-63472
Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
MEDIUM 5.3
CVE-2026-63461
Vendure: Shop API list queries can return non-public entities when filterOperator is OR
CRITICAL 9.1
CVE-2026-40887
@vendure/core has a SQL Injection vulnerability
UNKNOWN
CVE-2026-25050
Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy
MEDIUM 5.3
GHSA-wm63-7627-ch33
@vendure/core's insecure currencyCode handling allows wrong payment amounts
UNKNOWN
GHSA-h9wq-xcqx-mqxm
Vendure Cross Site Request Forgery vulnerability impacting all API requests
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes