Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.9 CVE-2026-31889 Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specif… Shopware 6.6.10.15 / 6.7.8.1+ Fix from $1,9502026-03-11 MEDIUM 5.3 CVE-2026-31888 Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different… Shopware 6.6.10.15 / 6.7.8.1+ Fix from $1,6002026-03-11 HIGH 7.5 CVE-2026-31887 Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows… Shopware 6.6.10.15 / 6.7.8.1+ Fix from $1,9502026-03-11 HIGH 7.2 CVE-2026-23498 Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure … Shopware 6.7.6.1+ Fix from $1,9502026-01-14 MEDIUM 6.1 CVE-2025-67648 Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthContro… Shopware 6.6.10.10 / 6.7.5.1+ Fix from $1,6002025-12-11 HIGH 8.1 CVE-2025-7954 A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended vouche… Shopware 6.7.2.0+ Fix from $1,9502025-08-06 MEDIUM 6.1 CVE-2025-51541 A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c… Shopware 6.2.3+ Fix from $1,6002025-08-05 MEDIUM 6.8 CVE-2025-27892EPSS 12% Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of… Shopware 6.5.8.17 / 6.6.10.3+ Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-32378 Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolic… Shopware 6.5.8.17 / 6.6.10.3+ Fix from $1,6002025-04-09 HIGH 7.5 CVE-2025-30151 Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-AP… Shopware 6.5.8.17 / 6.6.10.3+ Fix from $1,9502025-04-08 MEDIUM 5.3 CVE-2025-30150 Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific… Shopware 6.5.8.18 / 6.6.10.3+ Fix from $1,6002025-04-08 CRITICAL 9.8 CVE-2024-42355 Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Pr… Shopware 6.5.8.13 / 6.6.5.1+ Fix from $2,3002024-08-08 CRITICAL 9.8 CVE-2024-42357 Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which ena… Shopware 6.5.8.13 / 6.6.5.1+ Fix from $2,3002024-08-08 HIGH 7.2 CVE-2024-42356 Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and a… Shopware 6.5.8.13 / 6.6.5.1+ Fix from $1,9502024-08-08 MEDIUM 5.9 CVE-2024-42354 Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be mark… Shopware 6.5.8.13 / 6.6.5.1+ Fix from $1,6002024-08-08 MEDIUM 5.3 CVE-2024-31447 Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, wh… Shopware 6.5.8.8 / 6.6.1.0+ Fix from $1,6002024-04-08 HIGH 7.5 CVE-2024-27917 Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the R… Shopware 6.5.8.7+ Fix from $1,9502024-03-06 CRITICAL 9.8 CVE-2024-22406 Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through in… Shopware 6.5.7.4+ Fix from $2,3002024-01-16 HIGH 8.1 CVE-2024-22408 Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate t… Shopware 6.5.7.4+ Fix from $1,9502024-01-16 MEDIUM 6.5 CVE-2024-22407 Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations fo… Shopware 6.5.7.4+ Fix from $1,6002024-01-16 MEDIUM 5.3 CVE-2023-34098 Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript c… Shopware 5.7.18+ Fix from $1,6002023-06-27 MEDIUM 5.3 CVE-2023-34099 Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it was possible to construct diffe… Shopware after 5.7.17 Fix from $1,6002023-06-27 MEDIUM 6.1 CVE-2022-48150 Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI. Shopware No fix yet Fix from $1,6002023-04-21 HIGH 8.8 CVE-2023-2017 Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform … Shopware after 6.4.20.0 Fix from $1,9502023-04-17 HIGH 7.5 CVE-2023-23941 SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, S… Swagpaypal 5.4.4+ Fix from $1,9502023-02-03 CRITICAL 9.8 CVE-2023-22732 Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when a… Shopware 6.4.18.1+ Fix from $2,3002023-01-17 HIGH 7.5 CVE-2023-22734 Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly,… Shopware 6.4.18.1+ Fix from $1,9502023-01-17 MEDIUM 6.5 CVE-2023-22733 Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of s… Shopware 6.4.18.1+ Fix from $1,6002023-01-17 HIGH 8.8 CVE-2023-22731 Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is po… Shopware 6.4.18.1+ Fix from $1,9502023-01-17 HIGH 7.5 CVE-2023-22730 Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item mu… Shopware 6.4.18.1+ Fix from $1,9502023-01-17