Shopware

Shopware

67 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 09.03.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:00

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions it is possible to inject code via the voucher code form. This issue has been patched in version 6.4.8.1. There are no know...

  • EPSS 0.19%
  • Veröffentlicht 09.03.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:00

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inconsistent experiences for gues...

  • EPSS 0.16%
  • Veröffentlicht 09.03.2022 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:00

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue has been resolved in version 6...

  • EPSS 0.3%
  • Veröffentlicht 05.01.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:45:09

Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to th...

  • EPSS 0.26%
  • Veröffentlicht 05.01.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:45:09

Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to incomplete URL handling in the shopware router. This issue has been resolved in version 5.7.7. There...

  • EPSS 0.51%
  • Veröffentlicht 26.10.2021 15:15:10
  • Zuletzt bearbeitet 21.11.2024 06:25:43

Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5.7.6. Two workarounds are available. Using the security plugin or adding a particular following confi...

  • EPSS 0.52%
  • Veröffentlicht 16.08.2021 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:15:46

Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also av...

  • EPSS 0.32%
  • Veröffentlicht 16.08.2021 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:15:45

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding securit...

  • EPSS 0.22%
  • Veröffentlicht 16.08.2021 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:15:45

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch. As workarounds for older versi...

  • EPSS 7.81%
  • Veröffentlicht 16.08.2021 20:15:48
  • Zuletzt bearbeitet 21.11.2024 06:15:45

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding securit...