VYPR

Vendor CVEs

Shopware

All CVEs

80 total · sorted by risk
  • CVE-2016-3109CriApr 21, 2017
    risk 0.59cvss 9.8epss 0.28

    The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.

  • CVE-2023-2017HigApr 17, 2023
    risk 0.57cvss 8.8epss 0.02

    Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the…

  • CVE-2023-22731CriJan 17, 2023
    risk 0.57cvss 9.9epss 0.01

    Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows a template to call any global PHP…

  • CVE-2020-13970HigJul 28, 2020
    risk 0.57cvss 8.8epss 0.01

    Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.

  • CVE-2024-22406CriJan 16, 2024
    risk 0.54cvss 9.3epss 0.01

    Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in…

  • CVE-2025-7954HigAug 6, 2025
    risk 0.53cvss 8.1epss 0.00

    A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.

  • CVE-2021-32711CriJun 24, 2021
    risk 0.52cvss 9.1epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected…

  • CVE-2026-31889HigMar 11, 2026
    risk 0.51cvss 8.9epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow…

  • CVE-2021-37711HigAug 16, 2021
    risk 0.50cvss 8.8epss 0.01

    Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.

  • CVE-2021-37708HigAug 16, 2021
    risk 0.50cvss 8.8epss 0.02

    Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available…

  • CVE-2018-20713HigJan 15, 2019
    risk 0.50cvss 8.8epss 0.01

    Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.

  • CVE-2024-22408HigJan 16, 2024
    risk 0.49cvss 7.6epss 0.00

    Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate the URL used when creating the “call webhook” action. This enables malicious users to perform web requests to internal hosts.…

  • CVE-2022-24879HigApr 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is…

  • CVE-2020-13997HigJul 28, 2020
    risk 0.49cvss 7.5epss 0.01

    In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.

  • CVE-2019-12935HigJun 23, 2019
    risk 0.48cvss 7.4epss 0.03

    Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.

  • CVE-2024-42356HigAug 8, 2024
    risk 0.47cvss 8.3epss 0.01

    Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to access to current language, currency information. The context object allows also to switch for a short time the scope of…

  • CVE-2024-42355HigAug 8, 2024
    risk 0.47cvss 8.3epss 0.01

    Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag name to silence, but this parameter is not…

  • CVE-2017-18357MedJan 15, 2019
    risk 0.47cvss 6.5epss 0.27

    Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.

  • CVE-2022-24872HigApr 20, 2022
    risk 0.46cvss 8.1epss 0.01

    Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable within normal user session. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3,…

  • CVE-2021-37710HigAug 16, 2021
    risk 0.45cvss 8.0epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available…

  • CVE-2017-15374MedOct 16, 2017
    risk 0.43cvss 6.1epss 0.05

    Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remote attackers are able to inject malicious script code into the firstname, lastname, or order input fields to provoke persistent…

  • CVE-2026-48014MedJul 17, 2026
    risk 0.42cvss 6.5epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{transition} and similar transaction and delivery transition routes in src/Core/Checkout/Order/Api/OrderActionController.php do not…

  • CVE-2026-31887HigMar 11, 2026
    risk 0.42cvss 7.5epss 0.00

    Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability…

  • CVE-2025-30151HigApr 8, 2025
    risk 0.42cvss 7.5epss 0.00

    Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also…

  • CVE-2024-27917HigMar 6, 2024
    risk 0.42cvss 7.5epss 0.01

    Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the Response. Since Shopware 6.5.8.0, the 404 pages are cached to improve the performance of 404 pages. So the cached Response which…

  • CVE-2023-23941HigFeb 3, 2023
    risk 0.42cvss 7.5epss 0.00

    SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, Credit card), the amount and item list sent to PayPal may not be identical to the one in the created order.…

  • CVE-2022-24892MedApr 28, 2022
    risk 0.42cvss 6.4epss 0.01

    Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker to take over the victim's…

  • CVE-2022-24956MedMar 29, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability…

  • CVE-2021-32717HigJun 24, 2021
    risk 0.42cvss 7.5epss 0.01

    Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the…

  • CVE-2026-23498HigJan 14, 2026
    risk 0.40cvss 7.2epss 0.00

    Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure not checked being against allow list for the map(...) override. This vulnerability is fixed in 6.7.6.1.

  • CVE-2025-51541MedAug 5, 2025
    risk 0.40cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c_database_schema field fails to properly sanitize user-supplied input before rendering it in the browser, allowing an attacker to…

  • CVE-2024-42357HigAug 8, 2024
    risk 0.40cvss 7.3epss 0.01

    Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be…

  • CVE-2022-48150MedApr 21, 2023
    risk 0.40cvss 6.1epss 0.01

    Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI.

  • CVE-2022-24871HigApr 20, 2022
    risk 0.40cvss 7.2epss 0.01

    Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update internal resources. Users are advised to update to the current version 6.4.10.1. For older versions of…

  • CVE-2025-67648HigDec 11, 2025
    risk 0.39cvss 7.1epss 0.00

    Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template of the Storefront login page…

  • CVE-2025-27892MedApr 15, 2025
    risk 0.38cvss 6.8epss 0.12

    Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.

  • CVE-2026-48009MedJul 17, 2026
    risk 0.37cvss 6.8epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering POST /api/_action/user/user-recovery, reading the password recovery hash through POST…

  • CVE-2022-24748MedMar 9, 2022
    risk 0.37cvss 6.8epss 0.01

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possible to modify customers and to create orders without App Permission. This issue is a result of improper api route checking. Users…

  • CVE-2022-21651MedJan 5, 2022
    risk 0.37cvss 6.8epss 0.01

    Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to incomplete URL handling in the shopware router. This issue has been resolved in version 5.7.7. There is no workaround and users…

  • CVE-2026-48010MedJul 17, 2026
    risk 0.35cvss 6.5epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the admin field, so a non-admin API user with user:create or…

  • CVE-2026-48008MedJul 17, 2026
    risk 0.35cvss 6.5epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API POST /api/_action/sync; the regular integration…

  • CVE-2022-31057MedJun 27, 2022
    risk 0.35cvss 6.5epss 0.01

    Shopware is an open source e-commerce software made in Germany. Versions of Shopware 5 prior to version 5.7.12 are subject to an authenticated Stored XSS in Administration. Users are advised to upgrade. There are no known workarounds for this issue.

  • CVE-2022-24873MedApr 28, 2022
    risk 0.35cvss 5.4epss 0.01

    Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the…

  • CVE-2021-37709MedAug 16, 2021
    risk 0.35cvss 6.5epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3,…

  • CVE-2021-37707MedAug 16, 2021
    risk 0.35cvss 6.5epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability that allows manipulation of product reviews via API. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are…

  • CVE-2020-13971MedJul 28, 2020
    risk 0.35cvss 5.4epss 0.01

    In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.

  • CVE-2026-32142MedMar 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is fixed in 7.8.1 and 6.10.15.

  • CVE-2026-32100MedMar 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vulnerability is fixed in 2.0.16, 3.0.12, and 4.0.7.

  • CVE-2025-32378MedApr 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolicited newsletter sign-ups without confirmation. Default settings are Newsletter: Double Opt-in set to active, Newsletter: Double…

  • CVE-2022-36102MedSep 12, 2022
    risk 0.34cvss 6.3epss 0.01

    Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execute actions, which they are normally not able to do. Users are advised to update to the current…

Page 1 of 2