cbcvebase.

Shopware Platform vulnerabilities

51 known vulnerabilities affecting shopware/platform.

Total CVEs
51
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH20MEDIUM25LOW3

Vulnerabilities

Page 1 of 3
CVE-2025-27892P3HIGHPoC≥ 6.7.0.0-rc1, < 6.7.0.0-rc2≥ 6.6.0.0, < 6.6.10.3+1 more2025-04-08
CVE-2025-27892 [HIGH] CWE-89 Shopware Vulnerable to Blind SQL-injection in DAL aggregations Shopware Vulnerable to Blind SQL-injection in DAL aggregations ### Impact The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in the “aggregations” object. The ‘name’ field in this “aggregations” **in nested** object is vulnerabl
ghsaosv
CVE-2021-37708P2CRITICALCVSS 9.8≤ 6.4.3.02021-08-16
CVE-2021-37708 [CRITICAL] CWE-77 CVE-2021-37708: Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
ghsanvdosv
CVE-2023-2017P2HIGHCVSS 8.8≥ 0, < 6.4.20.12023-04-18
CVE-2023-2017 [HIGH] CWE-1336 Shopware Has Improper Control of Generation of Code in Twig rendered views Shopware Has Improper Control of Generation of Code in Twig rendered views ### Impact We fixed with [CVE-2023-22731](https://github.com/shopware/platform/security/advisories/GHSA-93cw-f5jj-x85w) Twig filters to only be executed with allowed functions. It is possible to pass PHP Closures as string or an array and array crafted PHP Closures was not checked against allow list ### Patches The p
ghsaosv
CVE-2026-31889P3HIGHCVSS 8.9v>= 6.7.0.0, < 6.7.8.1fixed in 6.6.10.152026-03-11
CVE-2026-31889 [HIGH] CWE-290 CVE-2026-31889: Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopwa Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow used HMAC‑based authentication without sufficiently binding a shop install
ghsanvdosv
CVE-2023-22731P3HIGHCVSS 8.8fixed in 6.4.18.12023-01-17
CVE-2023-22731 [HIGH] CWE-94 CVE-2023-22731: Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig enviro Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows a template to call any global PHP function and thus execute arbitrary code. The attacker must have access to a Twi
ghsanvdosv
CVE-2024-42355P3HIGH≥ 0, < 6.5.8.13≥ 6.6.0.0, < 6.6.5.12024-08-08
CVE-2024-42355 [HIGH] CWE-1336 Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag ### Impact Shopware has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. It accepts as parameter a string the feature flag name to silence, but this parameter is not escaped properly and allows execution of code. ### Patches U
ghsaosv
CVE-2024-42357P3MEDIUM≥ 0, < 6.5.8.13≥ 6.6.0.0, < 6.6.5.12024-08-08
CVE-2024-42357 [MEDIUM] CWE-89 Shopware vulnerable to blind SQL-injection in DAL aggregations Shopware vulnerable to blind SQL-injection in DAL aggregations ### Impact The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in the “aggregations” object. The ‘name’ field in this “aggregations” object is vulnerable SQL-inject
ghsaosv
CVE-2021-37711P3HIGHCVSS 8.8≤ 6.4.3.02021-08-16
CVE-2021-37711 [HIGH] CWE-918 CVE-2021-37711: Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
ghsanvdosv
CVE-2023-22732P3CRITICALCVSS 9.8fixed in 6.4.18.12023-01-17
CVE-2023-22732 [CRITICAL] CWE-613 CVE-2023-22732: Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administrati Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time. In version 6.4.18.1 an automatic logout into the Administration session has been added. As a result the user will
ghsanvdosv
CVE-2026-31887P3HIGHCVSS 7.5v>= 6.7.0.0, < 6.7.8.1fixed in 6.6.10.152026-03-11
CVE-2026-31887 [HIGH] CWE-863 CVE-2026-31887: Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability is fixed in 6.7.8.1 and 6.6.10.15.
ghsanvdosv
CVE-2024-22406P3CRITICAL≥ 0, < 6.5.7.42024-01-17
CVE-2024-22406 [CRITICAL] CWE-89 Blind SQL injection in shopware Blind SQL injection in shopware ### Impact The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in the “aggregations” object. The ‘name’ field in this “aggregations” object is vulnerable SQL-injection and can be exploited using time-based SQL-queries. ### P
ghsaosv
CVE-2022-24872P3HIGHCVSS 8.1fixed in 6.4.10.12022-04-20
CVE-2022-24872 [HIGH] CWE-732 CVE-2022-24872: Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales c Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable within normal user session. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. There are no
ghsanvdosv
CVE-2021-32717P3HIGHCVSS 7.5fixed in 6.4.1.12021-06-24
CVE-2021-32717 [HIGH] CWE-200 CVE-2021-32717: Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly a Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the documentation. The visibility must be at the same level as `type`. When the Stora
ghsanvdosv
CVE-2020-13970P3HIGH≥ 0, < 6.2.32022-05-24
CVE-2020-13970 [HIGH] CWE-918 Shopware vulnerable to SSRF Shopware vulnerable to SSRF Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.
ghsaosv
CVE-2026-48009P3MEDIUMCVSS 6.8fixed in 6.6.10.18v>= 6.7.0.0, < 6.7.10.12026-07-17
CVE-2026-48009 [MEDIUM] CWE-200 CVE-2026-48009: Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user w Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering POST /api/_action/user/user-recovery, reading the password recovery hash through POST /api/search/user-recovery, and using PATCH /api/_action/user/user-recovery/password; the roo
ghsanvd
CVE-2026-48008P3MEDIUMCVSS 6.5fixed in 6.6.10.18v>= 6.7.0.0, < 6.7.10.12026-07-17
CVE-2026-48008 [MEDIUM] CWE-862 CVE-2026-48008: Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with in Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API POST /api/_action/sync; the regular integration endpoint POST /api/integration blocks this, but SyncController::sync() r
ghsanvd
CVE-2021-32711P3HIGHCVSS 7.5fixed in 6.3.5.12021-06-24
CVE-2021-32711 [HIGH] CWE-200 CVE-2021-32711: Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected by this change. We recommend to update to the current version 6.3.5.1. You
ghsanvdosv
CVE-2021-37707P3HIGHCVSS 7.5≤ 6.4.3.02021-08-16
CVE-2021-37707 [HIGH] CWE-20 CVE-2021-37707: Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability tha Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability that allows manipulation of product reviews via API. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
ghsanvdosv
CVE-2022-24748P3HIGHCVSS 7.5fixed in 6.4.8.22022-03-09
CVE-2022-24748 [HIGH] CWE-287 CVE-2022-24748: Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript fram Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possible to modify customers and to create orders without App Permission. This issue is a result of improper api route checking. Users are advised to upgrade to version 6.4.8.2. There are no known workarounds.
nvd
CVE-2023-22730P3HIGHCVSS 7.5fixed in 6.4.18.12023-01-17
CVE-2023-22730 [HIGH] CWE-20 CVE-2023-22730: Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected vers Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item multiple times in the cart using the AP. The Cart Validators checked the line item's individuality and the user was able to bypass quantity limits in sales. This problem has been fixed with version 6.4.18.1.
ghsanvdosv
Shopware Platform vulnerabilities | cvebase