Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

shopware — Vulnerabilities & Security Advisories 38

All 38 CVE vulnerabilities found in shopware, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the shopware product, covering various weakness types and security tags. It collects a comprehensive history of security issues affecting the shopware platform, including known flaws, potential exploits, and their associated remediation details, spanning the full timeline of recorded advisories. Here, users can track the vendor's security advisories, understand specific weakness classes, and look up the complete vulnerability history for shopware. The collection provides structured information on how each vulnerability impacts the product, facilitating informed risk assessment.

Vendor: shopware

CVE ID Title CVSS Severity Published
CVE-2026-48012 Shopware SSO referer trust leading to an arbitrary redirect target CWE-601 4.3 Medium 2026-07-23
CVE-2026-48013 Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation CWE-918 4.1 Medium 2026-07-23
CVE-2026-48009 Shopware: Admin Account Takeover via User Recovery Hash Exposure CWE-200 6.8 Medium 2026-07-17
CVE-2026-48014 Shopware: Admin API ACL Bypass in Order State Transition Endpoints CWE-862 6.5 Medium 2026-07-17
CVE-2026-48010 Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts CWE-269 6.5 Medium 2026-07-17
CVE-2026-48016 Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment CWE-639 4.3 Medium 2026-07-17
CVE-2026-48015 Shopware: Stored XSS via SVG file upload — no SVG sanitization CWE-79 4.9 Medium 2026-07-17
CVE-2026-48008 Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass CWE-862 6.5 Medium 2026-07-17
CVE-2026-48011 Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames CWE-208 3.7 Low 2026-06-10
CVE-2026-23498 Shopware Improper Control of Generation of Code in Twig rendered views CWE-94 7.2 High 2026-01-14
CVE-2025-67648 Shopware's inproper input validation can lead to Reflected XSS through Storefront Login Page CWE-79 7.1 High 2025-12-10
CVE-2025-7954 Race Condition in Shopware Voucher Submission CWE-362 5.9AI Medium AI 2025-08-06
CVE-2025-32378 Shopware's default newsletter opt-in settings allow for mass sign-up abuse CWE-799 6.5AI Medium AI 2025-04-09
CVE-2025-30150 Shopware 6 allows attackers to check for registered accounts through the store-api CWE-204 5.3AI Medium AI 2025-04-08
CVE-2025-30151 Shopware allows Denial Of Service via password length CWE-20 7.5 High 2025-04-08
CVE-2024-42357 Shopware vulnerable to blind SQL-injection in DAL aggregations CWE-89 7.3 High 2024-08-08
CVE-2024-42356 Shopware vulnerable to Server Side Template Injection in Twig using Context functions CWE-1336 8.3 High 2024-08-08
CVE-2024-42355 Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag CWE-1336 8.3 High 2024-08-08
CVE-2024-42354 Shopware vulnerable to Improper Access Control with ManyToMany associations in store-api CWE-284 5.3 Medium 2024-08-08
CVE-2024-31447 Shopware has Improper Session Handling in store-api CWE-613 5.3 Medium 2024-04-08
CVE-2024-27917 Shopware's session is persistent in Cache for 404 pages CWE-524 7.5 High 2024-03-06
CVE-2024-22406 Blind SQL-injection in DAL aggregations in Shopware CWE-89 9.3 Critical 2024-01-16
CVE-2024-22407 Broken Access Control order API in Shopware CWE-284 4.9 Medium 2024-01-16
CVE-2024-22408 Server-Side Request Forgery (SSRF) in Shopware Flow Builder CWE-918 7.6 High 2024-01-16
CVE-2023-34099 Improper mail validation in Shopware CWE-754 5.3 Medium 2023-06-27
CVE-2023-34098 Dependency configuration exposed in Shopware CWE-200 5.3 Medium 2023-06-27
CVE-2022-36102 Acess control list bypassed via crafted specific URLs CWE-281 6.3 Medium 2022-09-12
CVE-2022-36101 Sensitive data in backend customer module CWE-200 5.4 Medium 2022-09-12
CVE-2022-31148 Persistent cross site scripting in customer module in Shopware CWE-79 5.4 Medium 2022-08-01
CVE-2022-31057 Authenticated Stored XSS in Shopware Administration CWE-79 6.5 Medium 2022-06-27

All 38 known CVE vulnerabilities affecting shopware with full Chinese analysis, references, and POCs where available.