Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2022-36102 Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could b… Shopware 5.7.15+ Fix from $1,9502022-09-12 MEDIUM 5.3 CVE-2022-36101 Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained… Shopware 5.7.15+ Fix from $1,6002022-09-12 MEDIUM 5.4 CVE-2022-31148 Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerability exists in the customer m… Shopware 5.7.14+ Fix from $1,6002022-08-01 MEDIUM 5.4 CVE-2022-31057 Shopware is an open source e-commerce software made in Germany. Versions of Shopware 5 prior to version 5.7.12 are subject to an authenticated Stored… Shopware 5.7.12+ Fix from $1,6002022-06-27 HIGH 7.5 CVE-2022-24892 Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can… Shopware 5.7.9+ Fix from $1,9502022-04-28 HIGH 7.5 CVE-2022-24879 Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) t… Shopware 5.7.9+ Fix from $1,9502022-04-28 MEDIUM 6.1 CVE-2022-24873 Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the sto… Shopware 5.7.9+ Fix from $1,6002022-04-28 HIGH 8.1 CVE-2022-24872 Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable with… Shopware 6.4.10.1+ Fix from $1,9502022-04-20 MEDIUM 5.5 CVE-2022-24871 Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on t… Shopware 6.4.10.1+ Fix from $1,6002022-04-20 MEDIUM 6.5 CVE-2022-24956 An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQ… B2b Suite 1.5.1 / 2.0.7+ Fix from $1,6002022-03-29 HIGH 7.5 CVE-2022-24748 Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possibl… Shopware 6.4.8.2+ Fix from $1,9502022-03-09 MEDIUM 6.5 CVE-2022-24745 Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are sh… Shopware 6.4.8.2+ Fix from $1,6002022-03-09 MEDIUM 6.1 CVE-2022-24746 Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions it is possible to inj… Shopware 6.4.8.1+ Fix from $1,6002022-03-09 MEDIUM 5.3 CVE-2022-24747 Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no proper… Shopware 6.4.8.2+ Fix from $1,6002022-03-09 HIGH 8.1 CVE-2022-21652 Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password… Shopware 5.7.7+ Fix from $1,9502022-01-05 MEDIUM 6.1 CVE-2022-21651 Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to… Shopware 5.7.7+ Fix from $1,6002022-01-05 MEDIUM 5.4 CVE-2021-41188 Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5… Shopware 5.7.6+ Fix from $1,6002021-10-26 HIGH 8.8 CVE-2021-37711 Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch… Shopware 6.4.3.1+ Fix from $1,9502021-08-16 MEDIUM 5.4 CVE-2021-37710 Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.… Shopware 6.4.3.1+ Fix from $1,6002021-08-16 MEDIUM 6.5 CVE-2021-37709 Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log… Shopware 6.4.3.1+ Fix from $1,6002021-08-16 CRITICAL 9.8 CVE-2021-37708 Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.… Shopware 6.4.3.1+ Fix from $2,3002021-08-16 HIGH 7.5 CVE-2021-37707 Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability that allows manipulation of product reviews via API.… Shopware 6.4.3.1+ Fix from $1,9502021-08-16 HIGH 7.5 CVE-2021-32717 Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the h… Shopware 6.4.1.1+ Fix from $1,9502021-06-24 MEDIUM 5.3 CVE-2021-32712 Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in error handling. Users are rec… Shopware 5.6.10+ Fix from $1,6002021-06-24 HIGH 7.5 CVE-2021-32710 Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2. We recommend to update to th… Shopware 6.3.5.2+ Fix from $1,9502021-06-24 HIGH 7.5 CVE-2021-32711 Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed… Shopware 6.3.5.1+ Fix from $1,9502021-06-24 HIGH 8.8 CVE-2020-13970 Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated… Shopware 6.2.3+ Fix from $1,9502020-07-28 HIGH 7.5 CVE-2020-13997 In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enab… Shopware 6.2.3+ Fix from $1,9502020-07-28 MEDIUM 5.4 CVE-2020-13971 In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This… Shopware 6.2.3+ Fix from $1,6002020-07-28 MEDIUM 6.1 CVE-2019-12935 Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI. Shopware 5.5.8+ Fix from $1,6002019-06-23