VYPR

Shopware

by Shopware

Source repositories

CVEs (79)

  • CVE-2022-36101MedSep 12, 2022
    risk 0.28cvss 5.4epss 0.01

    Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained sensitive data like the hashed password and the session ID. These fields are now explicitly unset in version 5.7.15. Users are…

  • CVE-2022-31148MedAug 1, 2022
    risk 0.28cvss 5.4epss 0.01

    Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerability exists in the customer module. Users are recommend to update to the current version 5.7.14. You can get the update to 5.7.14 regularly via the…

  • CVE-2021-32712MedJun 24, 2021
    risk 0.28cvss 5.3epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in error handling. Users are recommend to update to version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via the download…

  • CVE-2026-31888MedMar 11, 2026
    risk 0.27cvss 5.3epss 0.00

    Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different error codes depending on whether the submitted email address belongs to a registered customer…

  • CVE-2025-30150MedApr 8, 2025
    risk 0.27cvss 5.3epss 0.00

    Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api endpoint /store-api/account/recovery-password you get the…

  • CVE-2024-42354MedAug 8, 2024
    risk 0.27cvss 5.3epss 0.00

    Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be marked as ApiAware in the EntityDefinition. So only ApiAware fields of the EntityDefinition will be encoded to the final JSON. Prior…

  • CVE-2024-31447MedApr 8, 2024
    risk 0.27cvss 5.3epss 0.01

    Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when a authenticated request is made to `POST /store-api/account/logout`, the cart will be cleared, but the User won't be logged…

  • CVE-2023-34098MedJun 27, 2023
    risk 0.27cvss 5.3epss 0.01

    Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript could be read in production environments (`themes/package-lock.json`). With this information, the specific Shopware version in a…

  • CVE-2024-22407MedJan 16, 2024
    risk 0.25cvss 4.9epss 0.00

    Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that modify the payment, delivery, and/or order status. Due to this inadequate implementation, users lacking 'write'…

  • CVE-2026-48011LowJun 10, 2026
    risk 0.24cvss 3.7epss 0.00

    Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.

  • CVE-2021-32713MedJun 24, 2021
    risk 0.24cvss 4.8epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 5.6.10 suffer from an authenticated stored XSS in administration vulnerability. Users are recommend to update to the version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via…

  • CVE-2021-32716MedJun 24, 2021
    risk 0.22cvss 4.4epss 0.01

    Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.1. You can get the update to 6.4.1.1…

  • CVE-2023-22734MedJan 17, 2023
    risk 0.21cvss 4.3epss 0.01

    Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly, and it was possible to skip the complete double opt in process. As a result operators may have inconsistencies in their…

  • CVE-2026-48013MedJul 23, 2026
    risk 0.20cvss 4.1epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP addresses. While the parallel `uploadFromURL` flow validates…

  • CVE-2023-22732LowJan 17, 2023
    risk 0.17cvss 3.7epss 0.01

    Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time. In version 6.4.18.1 an automatic logout into…

  • CVE-2022-21652LowJan 5, 2022
    risk 0.16cvss 3.5epss 0.01

    Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to the latest password change of a…

  • CVE-2023-22733LowJan 17, 2023
    risk 0.11cvss 2.7epss 0.01

    Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of sent mails. An attacker with access to either the local system logs or a centralized logging store may have access to other users…

  • CVE-2022-24744LowMar 9, 2022
    risk 0.10cvss 2.6epss 0.00

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue has been resolved in version 6.4.8.1. For older versions of…

  • CVE-2019-12799HigJun 13, 2019
    risk 0.07cvss 8.8epss 0.55

    In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to…

Page 4 of 4