Shopware
by Shopware
Source repositories
CVEs (79)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-3109 | Cri | 0.59 | 9.8 | 0.28 | Apr 21, 2017 | The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code. | ||
| CVE-2023-2017 | Hig | 0.57 | 8.8 | 0.02 | Apr 17, 2023 | Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the… | ||
| CVE-2023-22731 | Cri | 0.57 | 9.9 | 0.01 | Jan 17, 2023 | Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows a template to call any global PHP… | ||
| CVE-2020-13970 | Hig | 0.57 | 8.8 | 0.01 | Jul 28, 2020 | Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server. | ||
| CVE-2024-22406 | Cri | 0.54 | 9.3 | 0.01 | Jan 16, 2024 | Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in… | ||
| CVE-2025-7954 | Hig | 0.53 | 8.1 | 0.00 | Aug 6, 2025 | A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations. | ||
| CVE-2021-32711 | Cri | 0.52 | 9.1 | 0.01 | Jun 24, 2021 | Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected… | ||
| CVE-2026-31889 | Hig | 0.51 | 8.9 | 0.00 | Mar 11, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow… | ||
| CVE-2021-37711 | Hig | 0.50 | 8.8 | 0.01 | Aug 16, 2021 | Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. | ||
| CVE-2021-37708 | Hig | 0.50 | 8.8 | 0.02 | Aug 16, 2021 | Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available… | ||
| CVE-2018-20713 | Hig | 0.50 | 8.8 | 0.01 | Jan 15, 2019 | Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404. | ||
| CVE-2024-22408 | Hig | 0.49 | 7.6 | 0.00 | Jan 16, 2024 | Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate the URL used when creating the “call webhook” action. This enables malicious users to perform web requests to internal hosts.… | ||
| CVE-2022-24879 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2022 | Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is… | ||
| CVE-2020-13997 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2020 | In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled. | ||
| CVE-2019-12935 | Hig | 0.48 | 7.4 | 0.03 | Jun 23, 2019 | Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI. | ||
| CVE-2024-42356 | Hig | 0.47 | 8.3 | 0.01 | Aug 8, 2024 | Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to access to current language, currency information. The context object allows also to switch for a short time the scope of… | ||
| CVE-2024-42355 | Hig | 0.47 | 8.3 | 0.01 | Aug 8, 2024 | Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag name to silence, but this parameter is not… | ||
| CVE-2017-18357 | Med | 0.47 | 6.5 | 0.27 | Jan 15, 2019 | Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object. | ||
| CVE-2022-24872 | Hig | 0.46 | 8.1 | 0.01 | Apr 20, 2022 | Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable within normal user session. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3,… | ||
| CVE-2021-37710 | Hig | 0.45 | 8.0 | 0.01 | Aug 16, 2021 | Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available… |
- risk 0.59cvss 9.8epss 0.28
The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
- risk 0.57cvss 8.8epss 0.02
Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the…
- risk 0.57cvss 9.9epss 0.01
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows a template to call any global PHP…
- risk 0.57cvss 8.8epss 0.01
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.
- risk 0.54cvss 9.3epss 0.01
Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in…
- risk 0.53cvss 8.1epss 0.00
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
- risk 0.52cvss 9.1epss 0.01
Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected…
- risk 0.51cvss 8.9epss 0.00
Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow…
- risk 0.50cvss 8.8epss 0.01
Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
- risk 0.50cvss 8.8epss 0.02
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available…
- risk 0.50cvss 8.8epss 0.01
Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.
- risk 0.49cvss 7.6epss 0.00
Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate the URL used when creating the “call webhook” action. This enables malicious users to perform web requests to internal hosts.…
- risk 0.49cvss 7.5epss 0.01
Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is…
- risk 0.49cvss 7.5epss 0.01
In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.
- risk 0.48cvss 7.4epss 0.03
Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
- risk 0.47cvss 8.3epss 0.01
Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to access to current language, currency information. The context object allows also to switch for a short time the scope of…
- risk 0.47cvss 8.3epss 0.01
Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag name to silence, but this parameter is not…
- risk 0.47cvss 6.5epss 0.27
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.
- risk 0.46cvss 8.1epss 0.01
Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable within normal user session. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3,…
- risk 0.45cvss 8.0epss 0.01
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available…
Page 1 of 4