Shopware

Shopware

64 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 28.04.2022 15:15:10
  • Zuletzt bearbeitet 21.11.2024 06:51:20

Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker ...

  • EPSS 0.14%
  • Veröffentlicht 28.04.2022 15:15:09
  • Zuletzt bearbeitet 21.11.2024 06:51:18

Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validat...

  • EPSS 0.66%
  • Veröffentlicht 28.04.2022 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:17

Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vu...

  • EPSS 0.19%
  • Veröffentlicht 20.04.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:17

Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable within normal user session. Users are advised to update to the current version 6.4.10.1. For older versio...

  • EPSS 0.35%
  • Veröffentlicht 20.04.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:17

Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update internal resources. Users are advised to update to the current version 6....

  • EPSS 0.22%
  • Veröffentlicht 09.03.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:00

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possible to modify customers and to create orders without App Permission. This issue is a result of improper...

  • EPSS 0.33%
  • Veröffentlicht 09.03.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:00

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no properly set sensitive HTTP headers to be non-cacheable. If there is an HTTP cache between the server and c...

  • EPSS 0.66%
  • Veröffentlicht 09.03.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:00

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions it is possible to inject code via the voucher code form. This issue has been patched in version 6.4.8.1. There are no know...

  • EPSS 0.19%
  • Veröffentlicht 09.03.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:00

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inconsistent experiences for gues...

  • EPSS 0.16%
  • Veröffentlicht 09.03.2022 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:00

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue has been resolved in version 6...