Medium severity4.9NVD Advisory· Published Jul 17, 2026· Updated Jul 17, 2026
CVE-2026-48015
CVE-2026-48015
Description
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via the media manager without SVG content sanitization in the upload pipeline from MediaUploadController to FileSaver to TypeDetector, allowing malicious SVG JavaScript such as onload, , and to execute in the Shopware domain when the uploaded SVG is viewed. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shopware/corePackagist | >= 6.7.0.0, < 6.7.10.1 | 6.7.10.1 |
shopware/corePackagist | < 6.6.10.18 | 6.6.10.18 |
shopware/platformPackagist | >= 6.7.0.0, < 6.7.10.1 | 6.7.10.1 |
shopware/platformPackagist | < 6.6.10.18 | 6.6.10.18 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-xvhc-gm7j-mhmcghsaADVISORY
- github.com/shopware/shopware/releases/tag/v6.6.10.18nvdWEB
- github.com/shopware/shopware/releases/tag/v6.7.10.1nvdWEB
- github.com/shopware/shopware/security/advisories/GHSA-xvhc-gm7j-mhmcnvdWEB
- github.com/shopware/shopware/commit/745a3ea3b77d4fe0f78c595ef527d8453a134497nvd
- github.com/shopware/shopware/commit/fd6d39bdb62dfa06fe62c7c87b37607d84094cdanvd
News mentions
1- Shopware: Nine Vulnerabilities Disclosed, Including Privilege Escalation and XSSVypr Intelligence · Jun 4, 2026