cbcvebase.
CVE-2025-30151
published 2025-04-08

CVE-2025-30151: Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This…

PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.39%
31.5th percentile
Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

Affected

11 ranges
VendorProductVersion rangeFixed in
shopwarecore>= 0 < 6.5.8.176.5.8.17
shopwarecore>= 6.6.0.0 < 6.6.10.36.6.10.3
shopwarecore>= 6.7.0.0-rc1 < 6.7.0.0-rc26.7.0.0-rc2
shopwareplatform>= 0 < 6.5.8.176.5.8.17
shopwareplatform>= 6.6.0.0 < 6.6.10.36.6.10.3
shopwareplatform>= 6.7.0.0-rc1 < 6.7.0.0-rc26.7.0.0-rc2
shopwareshopware< 6.5.8.176.5.8.17
shopwareshopware
shopwareshopware
shopwareshopware
shopwareshopware>= 6.6.0.0 < 6.6.10.36.6.10.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.