{"api_version":"v1","generated_at":"2026-10-08T20:50:00+00:00","product":{"cve_count":12,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-automattic-woocommerce-1d3011ce54b2","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/woocommerce","name":"WooCommerce","next_cursor":null,"observations":[{"affected":"n/a < 11.1.0","affected_versions_present":true,"cve_id":"CVE-2026-48888","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48888","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-08T10:34:56.442Z","patch_url":"","primary_source":"","published":"2026-09-08T07:25:20.910Z"},{"affected":"n/a < 11.0","affected_versions_present":true,"cve_id":"CVE-2026-57777","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-57777","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-04T16:36:55.172Z","patch_url":"","primary_source":"","published":"2026-09-04T08:12:00.611Z"},{"affected":"5.4.0 < 5.4.4; 5.5.0 < 5.4.5; 5.6.0 < 5.6.3; 5.7.0 < 5.7.3; 5.8.0 < 5.8.2; 5.9.0 < 5.9.2; 6.0.0 < 6.0.2; 6.1.0 < 6.1.3","affected_versions_present":true,"cve_id":"CVE-2026-3589","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-3589","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-06T17:44:58.613Z","patch_url":"","primary_source":"","published":"2026-03-06T09:11:10.949Z"},{"affected":"8.1.0 < 8.1.3; 8.2.0 < 8.2.4; 8.3.0 < 8.3.3; 8.4.0 < 8.4.2; 8.5.0 < 8.5.4; 8.6.0 < 8.6.3; 8.7.0 < 8.7.2; 8.8.0 < 8.8.6","affected_versions_present":true,"cve_id":"CVE-2025-15033","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-15033","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-06T09:09:36.936Z","patch_url":"","primary_source":"","published":"2025-12-22T18:57:39.687Z"},{"affected":"\u2264 7.8.2","affected_versions_present":true,"cve_id":"CVE-2023-7320","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-7320","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-08T17:02:27.373Z","patch_url":"","primary_source":"","published":"2025-10-29T06:45:48.702Z"},{"affected":"\u2264 10.0.2","affected_versions_present":true,"cve_id":"CVE-2025-49042","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-49042","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:12:58.197Z","patch_url":"","primary_source":"","published":"2025-10-29T04:50:12.507Z"},{"affected":"\u2264 9.3.2; 9.4 \u2264 9.4.2","affected_versions_present":true,"cve_id":"CVE-2025-5062","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-5062","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-08T17:23:41.731Z","patch_url":"","primary_source":"","published":"2025-05-22T03:42:08.044Z"},{"affected":"\u2264 9.7.0","affected_versions_present":true,"cve_id":"CVE-2025-26762","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-26762","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:11:40.353Z","patch_url":"","primary_source":"","published":"2025-03-27T15:52:22.683Z"},{"affected":"\u2264 9.0.2","affected_versions_present":true,"cve_id":"CVE-2024-9944","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-9944","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-08T17:17:17.415Z","patch_url":"https://github.com/woocommerce/woocommerce/pull/49370","primary_source":"","published":"2024-10-15T05:31:31.921Z"},{"affected":"n/a \u2264 9.1.2","affected_versions_present":true,"cve_id":"CVE-2024-39666","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-39666","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:10:08.243Z","patch_url":"","primary_source":"","published":"2024-08-18T13:37:18.254Z"},{"affected":"n/a \u2264 8.9.2","affected_versions_present":true,"cve_id":"CVE-2024-35777","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-35777","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:09:55.316Z","patch_url":"","primary_source":"","published":"2024-07-09T09:57:21.810Z"},{"affected":"n/a \u2264 8.5.2","affected_versions_present":true,"cve_id":"CVE-2024-22155","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-22155","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:09:08.800Z","patch_url":"","primary_source":"","published":"2024-04-07T17:56:05.844Z"},{"affected":"n/a \u2264 8.2.2","affected_versions_present":true,"cve_id":"CVE-2023-52222","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-52222","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:09:07.249Z","patch_url":"","primary_source":"","published":"2024-01-08T18:53:05.442Z"},{"affected":"n/a \u2264 8.1.1; n/a \u2264 11.1.1","affected_versions_present":true,"cve_id":"CVE-2023-47777","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-47777","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:08:51.789Z","patch_url":"","primary_source":"","published":"2023-11-30T11:56:53.604Z"},{"affected":"5.2.0 < 5.2.0","affected_versions_present":true,"cve_id":"CVE-2021-24323","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-24323","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-03T19:28:23.704Z","patch_url":"","primary_source":"","published":"2021-05-17T16:48:53.000Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"automattic"}}
