All 38 CVE vulnerabilities found in shopware, with AI-generated Chinese analysis, references, and POCs.
This page aggregates vulnerability data for the shopware product, covering various weakness types and security tags. It collects a comprehensive history of security issues affecting the shopware platform, including known flaws, potential exploits, and their associated remediation details, spanning the full timeline of recorded advisories. Here, users can track the vendor's security advisories, understand specific weakness classes, and look up the complete vulnerability history for shopware. The collection provides structured information on how each vulnerability impacts the product, facilitating informed risk assessment.
Vendor: shopware
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2022-24892 | Multiple valid tokens for password reset in Shopware CWE-640 | 6.4 | Medium | 2022-04-28 |
| CVE-2022-24879 | Malfunction of Cross-Site Request Forgery token validation CWE-352 | 7.5 | High | 2022-04-28 |
| CVE-2022-24873 | Non-Stored Cross-site Scripting in Shopware storefront CWE-79 | 5.4 | Medium | 2022-04-28 |
| CVE-2022-21652 | Insufficient Session Expiration in shopware CWE-613 | 3.5 | Low | 2022-01-05 |
| CVE-2022-21651 | Open redirect in shopware CWE-601 | 6.8 | Medium | 2022-01-05 |
| CVE-2021-41188 | Authenticated Stored XSS in Administration CWE-79 | 5.7 | Medium | 2021-10-26 |
| CVE-2021-32712 | Information leakage in Error Handler CWE-200 | 5.3 | Medium | 2021-06-24 |
| CVE-2021-32713 | Authenticated Stored XSS CWE-79 | 4.8 | Medium | 2021-06-24 |
All 38 known CVE vulnerabilities affecting shopware with full Chinese analysis, references, and POCs where available.