CVE-2026-31889
- EPSS 0.07%
- Veröffentlicht 11.03.2026 18:56:23
- Zuletzt bearbeitet 16.03.2026 20:18:18
Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The ...
CVE-2026-31888
- EPSS 0.05%
- Veröffentlicht 11.03.2026 18:53:03
- Zuletzt bearbeitet 16.03.2026 20:37:21
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different error codes depending on whether the submitted email address belongs to a registered customer (CHECK...
CVE-2026-31887
- EPSS 0.05%
- Veröffentlicht 11.03.2026 18:49:46
- Zuletzt bearbeitet 16.03.2026 20:39:53
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order...
CVE-2026-23498
- EPSS 0.07%
- Veröffentlicht 14.01.2026 18:31:19
- Zuletzt bearbeitet 28.01.2026 17:17:16
Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure not checked being against allow list for the map(...) override. This vulnerability is fixed in 6.7.6....
CVE-2025-67648
- EPSS 0.05%
- Veröffentlicht 10.12.2025 23:55:10
- Zuletzt bearbeitet 17.03.2026 19:43:54
Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template o...
CVE-2025-7954
- EPSS 0.05%
- Veröffentlicht 06.08.2025 07:16:09
- Zuletzt bearbeitet 03.11.2025 20:19:21
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
CVE-2025-51541
- EPSS 0.12%
- Veröffentlicht 05.08.2025 00:00:00
- Zuletzt bearbeitet 10.09.2025 15:30:14
A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c_database_schema field fails to properly sanitize user-supplied input before rendering it in the brow...
CVE-2025-27892
- EPSS 2.79%
- Veröffentlicht 15.04.2025 00:00:00
- Zuletzt bearbeitet 23.04.2025 16:30:45
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.
CVE-2025-32378
- EPSS 0.12%
- Veröffentlicht 09.04.2025 15:37:44
- Zuletzt bearbeitet 10.09.2025 15:27:54
Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolicited newsletter sign-ups without confirmation. Default settings are Newsletter: Double Opt-in set to ...
CVE-2025-30150
- EPSS 0.33%
- Veröffentlicht 08.04.2025 13:46:44
- Zuletzt bearbeitet 10.09.2025 15:24:57
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api endpoint /store-api/account/recovery-...