High severity8.0NVD Advisory· Published Aug 16, 2021· Updated Jun 17, 2026
CVE-2021-37710
CVE-2021-37710
Description
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shopware/corePackagist | < 6.4.3.1 | 6.4.3.1 |
shopware/platformPackagist | < 6.4.3.1 | 6.4.3.1 |
Affected products
4- shopware/platformv5Range: <= 6.4.3.0
- ghsa-coords2 versions
< 6.4.3.1+ 1 more
- (no CPE)range: < 6.4.3.1
- (no CPE)range: < 6.4.3.1
Patches
Vulnerability mechanics
References
4- github.com/shopware/platform/commit/abe9f69e1f667800f974acccd3047b4930e4b423nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-fc38-mxwr-pfhxghsaADVISORY
- github.com/shopware/platform/security/advisories/GHSA-fc38-mxwr-pfhxnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-37710ghsaADVISORY
News mentions
0No linked articles in our index yet.