Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.9
CVE-2026-31889
Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specif…
Shopware
6.6.10.15 / 6.7.8.1+
MEDIUM 5.3
CVE-2026-31888
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different…
Shopware
6.6.10.15 / 6.7.8.1+
HIGH 7.5
CVE-2026-31887
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows…
Shopware
6.6.10.15 / 6.7.8.1+
HIGH 7.2
CVE-2026-23498
Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure …
Shopware
6.7.6.1+
MEDIUM 6.1
CVE-2025-67648
Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthContro…
Shopware
6.6.10.10 / 6.7.5.1+
HIGH 8.1
CVE-2025-7954
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended vouche…
Shopware
6.7.2.0+
MEDIUM 6.1
CVE-2025-51541
A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c…
Shopware
6.2.3+
MEDIUM 6.8
CVE-2025-27892EPSS 12%
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of…
Shopware
6.5.8.17 / 6.6.10.3+
MEDIUM 5.3
CVE-2025-32378
Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolic…
Shopware
6.5.8.17 / 6.6.10.3+
HIGH 7.5
CVE-2025-30151
Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-AP…
Shopware
6.5.8.17 / 6.6.10.3+
MEDIUM 5.3
CVE-2025-30150
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific…
Shopware
6.5.8.18 / 6.6.10.3+
CRITICAL 9.8
CVE-2024-42355
Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Pr…
Shopware
6.5.8.13 / 6.6.5.1+
CRITICAL 9.8
CVE-2024-42357
Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which ena…
Shopware
6.5.8.13 / 6.6.5.1+
HIGH 7.2
CVE-2024-42356
Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and a…
Shopware
6.5.8.13 / 6.6.5.1+
MEDIUM 5.9
CVE-2024-42354
Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be mark…
Shopware
6.5.8.13 / 6.6.5.1+
MEDIUM 5.3
CVE-2024-31447
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, wh…
Shopware
6.5.8.8 / 6.6.1.0+
HIGH 7.5
CVE-2024-27917
Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the R…
Shopware
6.5.8.7+
CRITICAL 9.8
CVE-2024-22406
Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through in…
Shopware
6.5.7.4+
HIGH 8.1
CVE-2024-22408
Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate t…
Shopware
6.5.7.4+
MEDIUM 6.5
CVE-2024-22407
Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations fo…
Shopware
6.5.7.4+
MEDIUM 5.3
CVE-2023-34098
Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript c…
Shopware
5.7.18+
MEDIUM 5.3
CVE-2023-34099
Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it was possible to construct diffe…
Shopware
after 5.7.17
MEDIUM 6.1
CVE-2022-48150
Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI.
Shopware
No fix yet
HIGH 8.8
CVE-2023-2017
Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform …
Shopware
after 6.4.20.0
HIGH 7.5
CVE-2023-23941
SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, S…
Swagpaypal
5.4.4+
CRITICAL 9.8
CVE-2023-22732
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when a…
Shopware
6.4.18.1+
HIGH 7.5
CVE-2023-22734
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly,…
Shopware
6.4.18.1+
MEDIUM 6.5
CVE-2023-22733
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of s…
Shopware
6.4.18.1+
HIGH 8.8
CVE-2023-22731
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is po…
Shopware
6.4.18.1+
HIGH 7.5
CVE-2023-22730
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item mu…
Shopware
6.4.18.1+