Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
Shopware
HIGH 8.8
CVE-2019-12799EPSS 55%
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can …
Fix: after 5.6.0
Fix from $1,950
2019-06-13
Shopware
HIGH 8.8
CVE-2018-20713
Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.
Fix: 5.4.3+
Fix from $1,950
2019-01-15
Shopware
MEDIUM 6.5
CVE-2017-18357EPSS 27%
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backe…
Fix: 5.3.4+
Fix from $1,600
2019-01-15
Shopware
MEDIUM 6.1
CVE-2017-15374
Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remo…
No fix yet
Fix from $1,600
2017-10-16
Shopware
CRITICAL 9.8
CVE-2016-3109EPSS 28%
The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
Fix: after 5.1.4
Fix from $2,300
2017-04-21