CVE-2025-30151
published 2025-04-08CVE-2025-30151: Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.39%
31.5th percentile
Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| shopware | core | >= 0 < 6.5.8.17 | 6.5.8.17 |
| shopware | core | >= 6.6.0.0 < 6.6.10.3 | 6.6.10.3 |
| shopware | core | >= 6.7.0.0-rc1 < 6.7.0.0-rc2 | 6.7.0.0-rc2 |
| shopware | platform | >= 0 < 6.5.8.17 | 6.5.8.17 |
| shopware | platform | >= 6.6.0.0 < 6.6.10.3 | 6.6.10.3 |
| shopware | platform | >= 6.7.0.0-rc1 < 6.7.0.0-rc2 | 6.7.0.0-rc2 |
| shopware | shopware | < 6.5.8.17 | 6.5.8.17 |
| shopware | shopware | — | — |
| shopware | shopware | — | — |
| shopware | shopware | — | — |
| shopware | shopware | >= 6.6.0.0 < 6.6.10.3 | 6.6.10.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Shopware allows Denial Of Service via password length
osv·2025-04-08
CVE-2025-30151 [HIGH] Shopware allows Denial Of Service via password length
Shopware allows Denial Of Service via password length
### Impact
It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API.
### Patches
Update to Shopware 6.6.10.3 or 6.5.8.17
### Workarounds
For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
GHSA
Shopware allows Denial Of Service via password length
ghsa·2025-04-08
CVE-2025-30151 [HIGH] CWE-20 Shopware allows Denial Of Service via password length
Shopware allows Denial Of Service via password length
### Impact
It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API.
### Patches
Update to Shopware 6.6.10.3 or 6.5.8.17
### Workarounds
For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-08
Published