4.9
CVE-2026-48015
- EPSS 0.28%
- Veröffentlicht 17.07.2026 17:53:01
- Zuletzt bearbeitet 17.07.2026 19:17:15
- CVE-Watchlists
- Unerledigt
Shopware: Stored XSS via SVG file upload — no SVG sanitization
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via the media manager without SVG content sanitization in the upload pipeline from MediaUploadController to FileSaver to TypeDetector, allowing malicious SVG JavaScript such as onload, <script>, and <foreignObject> to execute in the Shopware domain when the uploaded SVG is viewed. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellershopware
≫
Produkt
shopware
Version
< 6.6.10.18
Status
affected
Version
>= 6.7.0.0, < 6.7.10.1
Status
affected
Herstellershopware
≫
Produkt
platform
Version
< 6.6.10.18
Status
affected
Version
>= 6.7.0.0, < 6.7.10.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.198 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://github.com/shopware/shopware/releases/tag/v6.6.10.18
https://github.com/shopware/shopware/releases/tag/v6.7.10.1
https://github.com/shopware/shopware/security/advisories/GHSA-xvhc-gm7j-mhmc
https://github.com/shopware/shopware/commit/745a3ea3b77d4fe0f78c595ef527d8453a134497
https://github.com/shopware/shopware/commit/fd6d39bdb62dfa06fe62c7c87b37607d84094cda