Shopware

Shopware

67 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Veröffentlicht 08.04.2025 13:46:30
  • Zuletzt bearbeitet 10.09.2025 15:26:36

Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding secu...

  • EPSS 0.7%
  • Veröffentlicht 08.08.2024 15:15:18
  • Zuletzt bearbeitet 12.08.2024 15:26:19

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performe...

  • EPSS 0.43%
  • Veröffentlicht 08.08.2024 15:15:18
  • Zuletzt bearbeitet 12.08.2024 15:34:08

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to access to current language, currency information. The context object allows also to switch f...

  • EPSS 1.05%
  • Veröffentlicht 08.08.2024 15:15:18
  • Zuletzt bearbeitet 12.08.2024 15:40:32

Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag name to silen...

  • EPSS 0.42%
  • Veröffentlicht 08.08.2024 15:15:17
  • Zuletzt bearbeitet 12.08.2024 15:49:58

Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be marked as ApiAware in the EntityDefinition. So only ApiAware fields of the EntityDefinition will be encod...

  • EPSS 0.16%
  • Veröffentlicht 08.04.2024 16:15:08
  • Zuletzt bearbeitet 10.09.2025 15:20:17

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when a authenticated request is made to `POST /store-api/account/logout`, the cart will be cleared, but...

  • EPSS 0.12%
  • Veröffentlicht 06.03.2024 20:15:48
  • Zuletzt bearbeitet 10.09.2025 15:17:23

Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the Response. Since Shopware 6.5.8.0, the 404 pages are cached to improve the performance of 404 pages. So...

  • EPSS 0.19%
  • Veröffentlicht 16.01.2024 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:56:13

Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate the URL used when creating the “call webhook” action. This enables malicious users to perform web requ...

  • EPSS 0.11%
  • Veröffentlicht 16.01.2024 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:56:13

Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that modify the payment, delivery, and/or order status. Due to this inadequate implementati...

  • EPSS 0.22%
  • Veröffentlicht 16.01.2024 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:56:13

Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggre...