Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Shopware HIGH 7.2
CVE-2022-36102

Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could b…

Fix: 5.7.15+
Fix from $1,950 2022-09-12
Shopware MEDIUM 5.3
CVE-2022-36101

Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained…

Fix: 5.7.15+
Fix from $1,600 2022-09-12
Shopware MEDIUM 5.4
CVE-2022-31148

Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerability exists in the customer m…

Fix: 5.7.14+
Fix from $1,600 2022-08-01
Shopware MEDIUM 5.4
CVE-2022-31057

Shopware is an open source e-commerce software made in Germany. Versions of Shopware 5 prior to version 5.7.12 are subject to an authenticated Stored…

Fix: 5.7.12+
Fix from $1,600 2022-06-27
Shopware HIGH 7.5
CVE-2022-24892

Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can…

Fix: 5.7.9+
Fix from $1,950 2022-04-28
Shopware HIGH 7.5
CVE-2022-24879

Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) t…

Fix: 5.7.9+
Fix from $1,950 2022-04-28
Shopware MEDIUM 6.1
CVE-2022-24873

Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the sto…

Fix: 5.7.9+
Fix from $1,600 2022-04-28
Shopware HIGH 8.1
CVE-2022-24872

Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable with…

Fix: 6.4.10.1+
Fix from $1,950 2022-04-20
Shopware MEDIUM 5.5
CVE-2022-24871

Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on t…

Fix: 6.4.10.1+
Fix from $1,600 2022-04-20
B2b Suite MEDIUM 6.5
CVE-2022-24956

An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQ…

Fix: 1.5.1 / 2.0.7+
Fix from $1,600 2022-03-29
Shopware HIGH 7.5
CVE-2022-24748

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possibl…

Fix: 6.4.8.2+
Fix from $1,950 2022-03-09
Shopware MEDIUM 6.5
CVE-2022-24745

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are sh…

Fix: 6.4.8.2+
Fix from $1,600 2022-03-09
Shopware MEDIUM 6.1
CVE-2022-24746

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions it is possible to inj…

Fix: 6.4.8.1+
Fix from $1,600 2022-03-09
Shopware MEDIUM 5.3
CVE-2022-24747

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no proper…

Fix: 6.4.8.2+
Fix from $1,600 2022-03-09
Shopware HIGH 8.1
CVE-2022-21652

Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password…

Fix: 5.7.7+
Fix from $1,950 2022-01-05
Shopware MEDIUM 6.1
CVE-2022-21651

Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to…

Fix: 5.7.7+
Fix from $1,600 2022-01-05
Shopware MEDIUM 5.4
CVE-2021-41188

Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5…

Fix: 5.7.6+
Fix from $1,600 2021-10-26
Shopware HIGH 8.8
CVE-2021-37711

Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch…

Fix: 6.4.3.1+
Fix from $1,950 2021-08-16
Shopware MEDIUM 5.4
CVE-2021-37710

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.…

Fix: 6.4.3.1+
Fix from $1,600 2021-08-16
Shopware MEDIUM 6.5
CVE-2021-37709

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log…

Fix: 6.4.3.1+
Fix from $1,600 2021-08-16
Shopware CRITICAL 9.8
CVE-2021-37708

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.…

Fix: 6.4.3.1+
Fix from $2,300 2021-08-16
Shopware HIGH 7.5
CVE-2021-37707

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability that allows manipulation of product reviews via API.…

Fix: 6.4.3.1+
Fix from $1,950 2021-08-16
Shopware HIGH 7.5
CVE-2021-32717

Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the h…

Fix: 6.4.1.1+
Fix from $1,950 2021-06-24
Shopware MEDIUM 5.3
CVE-2021-32712

Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in error handling. Users are rec…

Fix: 5.6.10+
Fix from $1,600 2021-06-24
Shopware HIGH 7.5
CVE-2021-32710

Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2. We recommend to update to th…

Fix: 6.3.5.2+
Fix from $1,950 2021-06-24
Shopware HIGH 7.5
CVE-2021-32711

Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed…

Fix: 6.3.5.1+
Fix from $1,950 2021-06-24
Shopware HIGH 8.8
CVE-2020-13970

Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated…

Fix: 6.2.3+
Fix from $1,950 2020-07-28
Shopware HIGH 7.5
CVE-2020-13997

In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enab…

Fix: 6.2.3+
Fix from $1,950 2020-07-28
Shopware MEDIUM 5.4
CVE-2020-13971

In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This…

Fix: 6.2.3+
Fix from $1,600 2020-07-28
Shopware MEDIUM 6.1
CVE-2019-12935

Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.

Fix: 5.5.8+
Fix from $1,600 2019-06-23