Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

shopware — Vulnerabilities & Security Advisories 65

Browse all 65 CVE security advisories affecting shopware. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Shopware is an open-source e-commerce platform primarily utilized by mid-sized enterprises to manage online storefronts and complex product catalogs. Its architecture, built on PHP and Symfony components, has historically exposed it to a range of web application vulnerabilities, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection. Recent records indicate approximately 56 Common Vulnerabilities and Exposures (CVEs), reflecting ongoing challenges with input validation and access control mechanisms. Notable incidents often stem from insecure default configurations or delayed patching of critical plugins, allowing attackers to escalate privileges or execute arbitrary code. The platform’s modular extension system further complicates security hygiene, as third-party modules may introduce unvetted code paths. Consequently, administrators must rigorously audit dependencies and apply updates promptly to mitigate risks associated with its extensive feature set and frequent codebase modifications.

CVE ID Title CVSS Severity Published
CVE-2026-48012 Shopware SSO referer trust leading to an arbitrary redirect target — shopware CWE-601 4.3 Medium 2026-07-23
CVE-2026-48013 Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation — shopware CWE-918 4.1 Medium 2026-07-23
CVE-2026-48009 Shopware: Admin Account Takeover via User Recovery Hash Exposure — shopware CWE-200 6.8 Medium 2026-07-17
CVE-2026-48014 Shopware: Admin API ACL Bypass in Order State Transition Endpoints — shopware CWE-862 6.5 Medium 2026-07-17
CVE-2026-48010 Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts — shopware CWE-269 6.5 Medium 2026-07-17
CVE-2026-48016 Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment — shopware CWE-639 4.3 Medium 2026-07-17
CVE-2026-48015 Shopware: Stored XSS via SVG file upload — no SVG sanitization — shopware CWE-79 4.9 Medium 2026-07-17
CVE-2026-48008 Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass — shopware CWE-862 6.5 Medium 2026-07-17
CVE-2026-48011 Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames — shopware CWE-208 3.7 Low 2026-06-10
CVE-2026-32142 shopware/commercial: `/api/_info/config` route exposes information about licenses — commercial CWE-200 5.3 Medium 2026-03-12
CVE-2026-31889 Shopware has a potential take over of app credentials — core CWE-290 8.9 High 2026-03-11
CVE-2026-31888 Shopware has user enumeration via distinct error codes on Store API login endpoint — core CWE-204 5.3 Medium 2026-03-11
CVE-2026-31887 Shopware unauthenticated data extraction possible through store-api.order endpoint — core CWE-863 9.1AI Critical AI 2026-03-11
CVE-2026-23498 Shopware Improper Control of Generation of Code in Twig rendered views — shopware CWE-94 7.2 High 2026-01-14
CVE-2025-67648 Shopware's inproper input validation can lead to Reflected XSS through Storefront Login Page — shopware CWE-79 7.1 High 2025-12-10
CVE-2025-7954 Race Condition in Shopware Voucher Submission — Shopware CWE-362 5.9AI Medium AI 2025-08-06
CVE-2025-32378 Shopware's default newsletter opt-in settings allow for mass sign-up abuse — shopware CWE-799 6.5AI Medium AI 2025-04-09
CVE-2025-30150 Shopware 6 allows attackers to check for registered accounts through the store-api — shopware CWE-204 5.3AI Medium AI 2025-04-08
CVE-2025-30151 Shopware allows Denial Of Service via password length — shopware CWE-20 7.5 High 2025-04-08
CVE-2024-42357 Shopware vulnerable to blind SQL-injection in DAL aggregations — shopware CWE-89 7.3 High 2024-08-08
CVE-2024-42356 Shopware vulnerable to Server Side Template Injection in Twig using Context functions — shopware CWE-1336 8.3 High 2024-08-08
CVE-2024-42355 Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag — shopware CWE-1336 8.3 High 2024-08-08
CVE-2024-42354 Shopware vulnerable to Improper Access Control with ManyToMany associations in store-api — shopware CWE-284 5.3 Medium 2024-08-08
CVE-2024-31447 Shopware has Improper Session Handling in store-api — shopware CWE-613 5.3 Medium 2024-04-08
CVE-2024-27917 Shopware's session is persistent in Cache for 404 pages — shopware CWE-524 7.5 High 2024-03-06
CVE-2024-22406 Blind SQL-injection in DAL aggregations in Shopware — shopware CWE-89 9.3 Critical 2024-01-16
CVE-2024-22407 Broken Access Control order API in Shopware — shopware CWE-284 4.9 Medium 2024-01-16
CVE-2024-22408 Server-Side Request Forgery (SSRF) in Shopware Flow Builder — shopware CWE-918 7.6 High 2024-01-16
CVE-2023-34099 Improper mail validation in Shopware — shopware CWE-754 5.3 Medium 2023-06-27
CVE-2023-34098 Dependency configuration exposed in Shopware — shopware CWE-200 5.3 Medium 2023-06-27

This page lists every published CVE security advisory associated with shopware. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.