Shopware

Shopware

64 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.05%
  • Veröffentlicht 08.08.2024 15:15:18
  • Zuletzt bearbeitet 12.08.2024 15:40:32

Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag name to silen...

  • EPSS 0.42%
  • Veröffentlicht 08.08.2024 15:15:17
  • Zuletzt bearbeitet 12.08.2024 15:49:58

Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be marked as ApiAware in the EntityDefinition. So only ApiAware fields of the EntityDefinition will be encod...

  • EPSS 0.16%
  • Veröffentlicht 08.04.2024 16:15:08
  • Zuletzt bearbeitet 10.09.2025 15:20:17

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when a authenticated request is made to `POST /store-api/account/logout`, the cart will be cleared, but...

  • EPSS 0.12%
  • Veröffentlicht 06.03.2024 20:15:48
  • Zuletzt bearbeitet 10.09.2025 15:17:23

Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the Response. Since Shopware 6.5.8.0, the 404 pages are cached to improve the performance of 404 pages. So...

  • EPSS 0.11%
  • Veröffentlicht 16.01.2024 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:56:13

Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that modify the payment, delivery, and/or order status. Due to this inadequate implementati...

  • EPSS 0.22%
  • Veröffentlicht 16.01.2024 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:56:13

Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggre...

  • EPSS 0.19%
  • Veröffentlicht 16.01.2024 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:56:13

Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate the URL used when creating the “call webhook” action. This enables malicious users to perform web requ...

  • EPSS 0.11%
  • Veröffentlicht 27.06.2023 17:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:32

Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it was possible to construct different mail addresses, that in the end result in the same address, which is shared by multiple accounts...

  • EPSS 0.21%
  • Veröffentlicht 27.06.2023 17:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:32

Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript could be read in production environments (`themes/package-lock.json`). With this information, the spec...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 21.04.2023 14:15:07
  • Zuletzt bearbeitet 05.02.2025 15:15:16

Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI.