Shopware Core vulnerabilities
42 known vulnerabilities affecting shopware/core.
Total CVEs
42
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH14MEDIUM21LOW5
Vulnerabilities
Page 3 of 3
CVE-2026-48011P4LOW≥ 6.7.0.0, < 6.7.10.1≥ 0, < 6.6.10.182026-06-04
CVE-2026-48011 [LOW] CWE-208 Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames
Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames
### Summary
There is a Proof of Concept which is able to enumerate the usernames of administrator users. This was possible by performing a timing attack.
### Details
The faulty code exists in [`src/Core/Framework/Api/OAuth/UserRepository.php`](https://github.com/shopware/shopware/blob/trunk/src
ghsa
CVE-2022-24744P4LOW≥ 0, < 6.4.8.12022-03-10
CVE-2022-24744 [LOW] CWE-613 Shopware user session is not logged out if the password is reset via password recovery
Shopware user session is not logged out if the password is reset via password recovery
### Impact
User session is not logged out if the password is reset via password recovery
## Patches
Fixed in 6.4.8.1, maintainers recommend updating to the current version 6.4.8.2. You can get the update to 6.4.8.2 regularly via the Auto-Updater or directly via the download overview.
https://w
ghsaosv
← Previous3 / 3