Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Shopware HIGH 8.9
CVE-2026-31889

Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specif…

Fix: 6.6.10.15 / 6.7.8.1+
Fix from $1,950 2026-03-11
Shopware MEDIUM 5.3
CVE-2026-31888

Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different…

Fix: 6.6.10.15 / 6.7.8.1+
Fix from $1,600 2026-03-11
Shopware HIGH 7.5
CVE-2026-31887

Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows…

Fix: 6.6.10.15 / 6.7.8.1+
Fix from $1,950 2026-03-11
Shopware HIGH 7.2
CVE-2026-23498

Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure …

Fix: 6.7.6.1+
Fix from $1,950 2026-01-14
Shopware MEDIUM 6.1
CVE-2025-67648

Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthContro…

Fix: 6.6.10.10 / 6.7.5.1+
Fix from $1,600 2025-12-11
Shopware HIGH 8.1
CVE-2025-7954

A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended vouche…

Fix: 6.7.2.0+
Fix from $1,950 2025-08-06
Shopware MEDIUM 6.1
CVE-2025-51541

A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c…

Fix: 6.2.3+
Fix from $1,600 2025-08-05
Shopware MEDIUM 6.8
CVE-2025-27892EPSS 12%

Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of…

Fix: 6.5.8.17 / 6.6.10.3+
Fix from $1,600 2025-04-15
Shopware MEDIUM 5.3
CVE-2025-32378

Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolic…

Fix: 6.5.8.17 / 6.6.10.3+
Fix from $1,600 2025-04-09
Shopware HIGH 7.5
CVE-2025-30151

Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-AP…

Fix: 6.5.8.17 / 6.6.10.3+
Fix from $1,950 2025-04-08
Shopware MEDIUM 5.3
CVE-2025-30150

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific…

Fix: 6.5.8.18 / 6.6.10.3+
Fix from $1,600 2025-04-08
Shopware CRITICAL 9.8
CVE-2024-42355

Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Pr…

Fix: 6.5.8.13 / 6.6.5.1+
Fix from $2,300 2024-08-08
Shopware CRITICAL 9.8
CVE-2024-42357

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which ena…

Fix: 6.5.8.13 / 6.6.5.1+
Fix from $2,300 2024-08-08
Shopware HIGH 7.2
CVE-2024-42356

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and a…

Fix: 6.5.8.13 / 6.6.5.1+
Fix from $1,950 2024-08-08
Shopware MEDIUM 5.9
CVE-2024-42354

Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be mark…

Fix: 6.5.8.13 / 6.6.5.1+
Fix from $1,600 2024-08-08
Shopware MEDIUM 5.3
CVE-2024-31447

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, wh…

Fix: 6.5.8.8 / 6.6.1.0+
Fix from $1,600 2024-04-08
Shopware HIGH 7.5
CVE-2024-27917

Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the R…

Fix: 6.5.8.7+
Fix from $1,950 2024-03-06
Shopware CRITICAL 9.8
CVE-2024-22406

Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through in…

Fix: 6.5.7.4+
Fix from $2,300 2024-01-16
Shopware HIGH 8.1
CVE-2024-22408

Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate t…

Fix: 6.5.7.4+
Fix from $1,950 2024-01-16
Shopware MEDIUM 6.5
CVE-2024-22407

Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations fo…

Fix: 6.5.7.4+
Fix from $1,600 2024-01-16
Shopware MEDIUM 5.3
CVE-2023-34098

Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript c…

Fix: 5.7.18+
Fix from $1,600 2023-06-27
Shopware MEDIUM 5.3
CVE-2023-34099

Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it was possible to construct diffe…

Fix: after 5.7.17
Fix from $1,600 2023-06-27
Shopware MEDIUM 6.1
CVE-2022-48150

Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI.

No fix yet
Fix from $1,600 2023-04-21
Shopware HIGH 8.8
CVE-2023-2017

Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform …

Fix: after 6.4.20.0
Fix from $1,950 2023-04-17
Swagpaypal HIGH 7.5
CVE-2023-23941

SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, S…

Fix: 5.4.4+
Fix from $1,950 2023-02-03
Shopware CRITICAL 9.8
CVE-2023-22732

Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when a…

Fix: 6.4.18.1+
Fix from $2,300 2023-01-17
Shopware HIGH 7.5
CVE-2023-22734

Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly,…

Fix: 6.4.18.1+
Fix from $1,950 2023-01-17
Shopware MEDIUM 6.5
CVE-2023-22733

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of s…

Fix: 6.4.18.1+
Fix from $1,600 2023-01-17
Shopware HIGH 8.8
CVE-2023-22731

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is po…

Fix: 6.4.18.1+
Fix from $1,950 2023-01-17
Shopware HIGH 7.5
CVE-2023-22730

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item mu…

Fix: 6.4.18.1+
Fix from $1,950 2023-01-17