VYPR

Shopware

by Shopware

Source repositories

CVEs (79)

  • CVE-2022-31057MedJun 27, 2022
    risk 0.35cvss 6.5epss 0.01

    Shopware is an open source e-commerce software made in Germany. Versions of Shopware 5 prior to version 5.7.12 are subject to an authenticated Stored XSS in Administration. Users are advised to upgrade. There are no known workarounds for this issue.

  • CVE-2022-24873MedApr 28, 2022
    risk 0.35cvss 5.4epss 0.01

    Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the…

  • CVE-2021-37709MedAug 16, 2021
    risk 0.35cvss 6.5epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3,…

  • CVE-2021-37707MedAug 16, 2021
    risk 0.35cvss 6.5epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability that allows manipulation of product reviews via API. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are…

  • CVE-2020-13971MedJul 28, 2020
    risk 0.35cvss 5.4epss 0.01

    In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.

  • CVE-2026-32142MedMar 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is fixed in 7.8.1 and 6.10.15.

  • CVE-2026-32100MedMar 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vulnerability is fixed in 2.0.16, 3.0.12, and 4.0.7.

  • CVE-2025-32378MedApr 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolicited newsletter sign-ups without confirmation. Default settings are Newsletter: Double Opt-in set to active, Newsletter: Double…

  • CVE-2022-36102MedSep 12, 2022
    risk 0.34cvss 6.3epss 0.01

    Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execute actions, which they are normally not able to do. Users are advised to update to the current…

  • CVE-2022-24747MedMar 9, 2022
    risk 0.34cvss 6.3epss 0.01

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no properly set sensitive HTTP headers to be non-cacheable. If there is an HTTP cache between the server and client then headers may be…

  • CVE-2022-24746MedMar 9, 2022
    risk 0.33cvss 6.1epss 0.01

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions it is possible to inject code via the voucher code form. This issue has been patched in version 6.4.8.1. There are no known workarounds for this issue.

  • CVE-2026-48015MedJul 17, 2026
    risk 0.32cvss 4.9epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via the media manager without SVG content sanitization in the upload…

  • CVE-2021-32709MedJun 24, 2021
    risk 0.32cvss 4.9epss 0.01

    Shopware is an open source eCommerce platform. Creation of order credits was not validated by ACL in admin orders. Users are recommend to update to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download…

  • CVE-2022-24745MedMar 9, 2022
    risk 0.31cvss 4.8epss 0.01

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inconsistent experiences for guest users. Setups with Varnish…

  • CVE-2021-32710MedJun 24, 2021
    risk 0.31cvss 5.9epss 0.01

    Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2. We recommend to update to the current version 6.3.5.2. You can get the update to 6.3.5.2 regularly via the Auto-Updater or directly via the download overview.…

  • CVE-2021-41188MedOct 26, 2021
    risk 0.30cvss 5.7epss 0.01

    Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5.7.6. Two workarounds are available. Using the security plugin or adding a particular following config to the `.htaccess` file…

  • CVE-2026-48012MedJul 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is reached without the expected SSO session state, the application falls back to the request's…

  • CVE-2026-48016MedJul 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment in src/Core/Checkout/Payment/SalesChannel/HandlePaymentMethodRoute.php accepts a user-controlled orderId and forwards it to…

  • CVE-2023-34099MedJun 27, 2023
    risk 0.28cvss 5.3epss 0.01

    Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it was possible to construct different mail addresses, that in the end result in the same address, which is shared by multiple accounts. This issue has been…

  • CVE-2023-22730MedJan 17, 2023
    risk 0.28cvss 5.3epss 0.01

    Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item multiple times in the cart using the AP. The Cart Validators checked the line item's individuality and the user was able to bypass…