VYPR
Vendor

Shopware

Products
3
CVEs
80
Across products
81
Status
Private

Products

3

Recent CVEs

80
View all 80 CVEs →
  • CVE-2016-3109CriApr 21, 2017
    risk 0.59cvss 9.8epss 0.28

    The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.

  • CVE-2023-2017HigApr 17, 2023
    risk 0.57cvss 8.8epss 0.02

    Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the…

  • CVE-2023-22731CriJan 17, 2023
    risk 0.57cvss 9.9epss 0.01

    Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows a template to call any global PHP…

  • CVE-2020-13970HigJul 28, 2020
    risk 0.57cvss 8.8epss 0.01

    Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.

  • CVE-2024-22406CriJan 16, 2024
    risk 0.54cvss 9.3epss 0.01

    Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in…

  • CVE-2025-7954HigAug 6, 2025
    risk 0.53cvss 8.1epss 0.00

    A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.

  • CVE-2021-32711CriJun 24, 2021
    risk 0.52cvss 9.1epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected…

  • CVE-2026-31889HigMar 11, 2026
    risk 0.51cvss 8.9epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow…

  • CVE-2021-37711HigAug 16, 2021
    risk 0.50cvss 8.8epss 0.01

    Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.

  • CVE-2021-37708HigAug 16, 2021
    risk 0.50cvss 8.8epss 0.02

    Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available…

  • CVE-2018-20713HigJan 15, 2019
    risk 0.50cvss 8.8epss 0.01

    Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.

  • CVE-2024-22408HigJan 16, 2024
    risk 0.49cvss 7.6epss 0.00

    Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate the URL used when creating the “call webhook” action. This enables malicious users to perform web requests to internal hosts.…

  • CVE-2022-24879HigApr 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is…

  • CVE-2020-13997HigJul 28, 2020
    risk 0.49cvss 7.5epss 0.01

    In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.

  • CVE-2019-12935HigJun 23, 2019
    risk 0.48cvss 7.4epss 0.03

    Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.

  • CVE-2024-42356HigAug 8, 2024
    risk 0.47cvss 8.3epss 0.01

    Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to access to current language, currency information. The context object allows also to switch for a short time the scope of…

  • CVE-2024-42355HigAug 8, 2024
    risk 0.47cvss 8.3epss 0.01

    Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag name to silence, but this parameter is not…

  • CVE-2017-18357MedJan 15, 2019
    risk 0.47cvss 6.5epss 0.27

    Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.

  • CVE-2022-24872HigApr 20, 2022
    risk 0.46cvss 8.1epss 0.01

    Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable within normal user session. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3,…

  • CVE-2021-37710HigAug 16, 2021
    risk 0.45cvss 8.0epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available…