CVE-2026-48012
- EPSS 0.16%
- Veröffentlicht 23.07.2026 19:16:38
- Zuletzt bearbeitet 28.07.2026 16:17:16
Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is reached without the expected SSO session state, the application fal...
CVE-2026-48013
- EPSS 0.21%
- Veröffentlicht 23.07.2026 19:14:32
- Zuletzt bearbeitet 27.07.2026 20:32:11
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP addresses. While the parallel `up...
CVE-2026-48009
- EPSS 0.27%
- Veröffentlicht 17.07.2026 17:58:15
- Zuletzt bearbeitet 17.07.2026 20:17:19
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering POST /api/_action/user/user-recovery, reading the password recovery hash thro...
CVE-2026-48014
- EPSS 0.23%
- Veröffentlicht 17.07.2026 17:56:43
- Zuletzt bearbeitet 21.07.2026 03:16:41
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{transition} and similar transaction and delivery transition routes in src/Core/Checkout/Order/Api/OrderAct...
CVE-2026-48010
- EPSS 0.26%
- Veröffentlicht 17.07.2026 17:55:25
- Zuletzt bearbeitet 18.07.2026 00:16:48
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the admin field, so a non-admin API us...
CVE-2026-48016
- EPSS 0.24%
- Veröffentlicht 17.07.2026 17:54:21
- Zuletzt bearbeitet 20.07.2026 20:16:43
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment in src/Core/Checkout/Payment/SalesChannel/HandlePaymentMethodRoute.php accepts a user-controlled orderId and forwards it to src/C...
CVE-2026-48015
- EPSS 0.28%
- Veröffentlicht 17.07.2026 17:53:01
- Zuletzt bearbeitet 17.07.2026 19:17:15
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via the media manager without SVG content sani...
CVE-2026-48008
- EPSS 0.26%
- Veröffentlicht 17.07.2026 17:47:27
- Zuletzt bearbeitet 17.07.2026 20:17:19
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API POST /api/_action/s...
CVE-2026-48011
- EPSS 0.22%
- Veröffentlicht 10.06.2026 20:07:02
- Zuletzt bearbeitet 23.07.2026 09:10:00
Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.
CVE-2026-31889
- EPSS 0.27%
- Veröffentlicht 11.03.2026 18:56:23
- Zuletzt bearbeitet 16.03.2026 20:18:18
Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The ...