VYPR

Vendor CVEs

Shopware

All CVEs

80 total · sorted by risk
  • CVE-2022-24747MedMar 9, 2022
    risk 0.34cvss 6.3epss 0.01

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no properly set sensitive HTTP headers to be non-cacheable. If there is an HTTP cache between the server and client then headers may be…

  • CVE-2022-24746MedMar 9, 2022
    risk 0.33cvss 6.1epss 0.01

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions it is possible to inject code via the voucher code form. This issue has been patched in version 6.4.8.1. There are no known workarounds for this issue.

  • CVE-2026-48015MedJul 17, 2026
    risk 0.32cvss 4.9epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via the media manager without SVG content sanitization in the upload…

  • CVE-2021-32709MedJun 24, 2021
    risk 0.32cvss 4.9epss 0.01

    Shopware is an open source eCommerce platform. Creation of order credits was not validated by ACL in admin orders. Users are recommend to update to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download…

  • CVE-2022-24745MedMar 9, 2022
    risk 0.31cvss 4.8epss 0.01

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inconsistent experiences for guest users. Setups with Varnish…

  • CVE-2021-32710MedJun 24, 2021
    risk 0.31cvss 5.9epss 0.01

    Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2. We recommend to update to the current version 6.3.5.2. You can get the update to 6.3.5.2 regularly via the Auto-Updater or directly via the download overview.…

  • CVE-2021-41188MedOct 26, 2021
    risk 0.30cvss 5.7epss 0.01

    Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5.7.6. Two workarounds are available. Using the security plugin or adding a particular following config to the `.htaccess` file…

  • CVE-2026-48012MedJul 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is reached without the expected SSO session state, the application falls back to the request's…

  • CVE-2026-48016MedJul 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment in src/Core/Checkout/Payment/SalesChannel/HandlePaymentMethodRoute.php accepts a user-controlled orderId and forwards it to…

  • CVE-2023-34099MedJun 27, 2023
    risk 0.28cvss 5.3epss 0.01

    Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it was possible to construct different mail addresses, that in the end result in the same address, which is shared by multiple accounts. This issue has been…

  • CVE-2023-22730MedJan 17, 2023
    risk 0.28cvss 5.3epss 0.01

    Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item multiple times in the cart using the AP. The Cart Validators checked the line item's individuality and the user was able to bypass…

  • CVE-2022-36101MedSep 12, 2022
    risk 0.28cvss 5.4epss 0.01

    Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained sensitive data like the hashed password and the session ID. These fields are now explicitly unset in version 5.7.15. Users are…

  • CVE-2022-31148MedAug 1, 2022
    risk 0.28cvss 5.4epss 0.01

    Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerability exists in the customer module. Users are recommend to update to the current version 5.7.14. You can get the update to 5.7.14 regularly via the…

  • CVE-2021-32712MedJun 24, 2021
    risk 0.28cvss 5.3epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in error handling. Users are recommend to update to version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via the download…

  • CVE-2026-31888MedMar 11, 2026
    risk 0.27cvss 5.3epss 0.00

    Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different error codes depending on whether the submitted email address belongs to a registered customer…

  • CVE-2025-30150MedApr 8, 2025
    risk 0.27cvss 5.3epss 0.00

    Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api endpoint /store-api/account/recovery-password you get the…

  • CVE-2024-42354MedAug 8, 2024
    risk 0.27cvss 5.3epss 0.00

    Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be marked as ApiAware in the EntityDefinition. So only ApiAware fields of the EntityDefinition will be encoded to the final JSON. Prior…

  • CVE-2024-31447MedApr 8, 2024
    risk 0.27cvss 5.3epss 0.01

    Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when a authenticated request is made to `POST /store-api/account/logout`, the cart will be cleared, but the User won't be logged…

  • CVE-2023-34098MedJun 27, 2023
    risk 0.27cvss 5.3epss 0.01

    Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript could be read in production environments (`themes/package-lock.json`). With this information, the specific Shopware version in a…

  • CVE-2024-22407MedJan 16, 2024
    risk 0.25cvss 4.9epss 0.00

    Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that modify the payment, delivery, and/or order status. Due to this inadequate implementation, users lacking 'write'…

  • CVE-2026-48011LowJun 10, 2026
    risk 0.24cvss 3.7epss 0.00

    Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.

  • CVE-2021-32713MedJun 24, 2021
    risk 0.24cvss 4.8epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 5.6.10 suffer from an authenticated stored XSS in administration vulnerability. Users are recommend to update to the version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via…

  • CVE-2021-32716MedJun 24, 2021
    risk 0.22cvss 4.4epss 0.01

    Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.1. You can get the update to 6.4.1.1…

  • CVE-2023-22734MedJan 17, 2023
    risk 0.21cvss 4.3epss 0.01

    Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly, and it was possible to skip the complete double opt in process. As a result operators may have inconsistencies in their…

  • CVE-2026-48013MedJul 23, 2026
    risk 0.20cvss 4.1epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP addresses. While the parallel `uploadFromURL` flow validates…

  • CVE-2023-22732LowJan 17, 2023
    risk 0.17cvss 3.7epss 0.01

    Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time. In version 6.4.18.1 an automatic logout into…

  • CVE-2022-21652LowJan 5, 2022
    risk 0.16cvss 3.5epss 0.01

    Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to the latest password change of a…

  • CVE-2023-22733LowJan 17, 2023
    risk 0.11cvss 2.7epss 0.01

    Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of sent mails. An attacker with access to either the local system logs or a centralized logging store may have access to other users…

  • CVE-2022-24744LowMar 9, 2022
    risk 0.10cvss 2.6epss 0.00

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue has been resolved in version 6.4.8.1. For older versions of…

  • CVE-2019-12799HigJun 13, 2019
    risk 0.07cvss 8.8epss 0.55

    In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to…

Page 2 of 2