VYPR

Shopware

by Shopware

Source repositories

CVEs (79)

  • CVE-2017-15374MedOct 16, 2017
    risk 0.43cvss 6.1epss 0.05

    Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remote attackers are able to inject malicious script code into the firstname, lastname, or order input fields to provoke persistent…

  • CVE-2026-48014MedJul 17, 2026
    risk 0.42cvss 6.5epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{transition} and similar transaction and delivery transition routes in src/Core/Checkout/Order/Api/OrderActionController.php do not…

  • CVE-2026-31887HigMar 11, 2026
    risk 0.42cvss 7.5epss 0.00

    Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability…

  • CVE-2025-30151HigApr 8, 2025
    risk 0.42cvss 7.5epss 0.00

    Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also…

  • CVE-2024-27917HigMar 6, 2024
    risk 0.42cvss 7.5epss 0.01

    Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the Response. Since Shopware 6.5.8.0, the 404 pages are cached to improve the performance of 404 pages. So the cached Response which…

  • CVE-2022-24892MedApr 28, 2022
    risk 0.42cvss 6.4epss 0.01

    Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker to take over the victim's…

  • CVE-2022-24956MedMar 29, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability…

  • CVE-2021-32717HigJun 24, 2021
    risk 0.42cvss 7.5epss 0.01

    Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the…

  • CVE-2026-23498HigJan 14, 2026
    risk 0.40cvss 7.2epss 0.00

    Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure not checked being against allow list for the map(...) override. This vulnerability is fixed in 6.7.6.1.

  • CVE-2025-51541MedAug 5, 2025
    risk 0.40cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c_database_schema field fails to properly sanitize user-supplied input before rendering it in the browser, allowing an attacker to…

  • CVE-2024-42357HigAug 8, 2024
    risk 0.40cvss 7.3epss 0.01

    Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be…

  • CVE-2022-48150MedApr 21, 2023
    risk 0.40cvss 6.1epss 0.01

    Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI.

  • CVE-2022-24871HigApr 20, 2022
    risk 0.40cvss 7.2epss 0.01

    Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update internal resources. Users are advised to update to the current version 6.4.10.1. For older versions of…

  • CVE-2025-67648HigDec 11, 2025
    risk 0.39cvss 7.1epss 0.00

    Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template of the Storefront login page…

  • CVE-2025-27892MedApr 15, 2025
    risk 0.38cvss 6.8epss 0.12

    Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.

  • CVE-2026-48009MedJul 17, 2026
    risk 0.37cvss 6.8epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering POST /api/_action/user/user-recovery, reading the password recovery hash through POST…

  • CVE-2022-24748MedMar 9, 2022
    risk 0.37cvss 6.8epss 0.01

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possible to modify customers and to create orders without App Permission. This issue is a result of improper api route checking. Users…

  • CVE-2022-21651MedJan 5, 2022
    risk 0.37cvss 6.8epss 0.01

    Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to incomplete URL handling in the shopware router. This issue has been resolved in version 5.7.7. There is no workaround and users…

  • CVE-2026-48010MedJul 17, 2026
    risk 0.35cvss 6.5epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the admin field, so a non-admin API user with user:create or…

  • CVE-2026-48008MedJul 17, 2026
    risk 0.35cvss 6.5epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API POST /api/_action/sync; the regular integration…