Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

shopware — Vulnerabilities & Security Advisories 65

Browse all 65 CVE security advisories affecting shopware. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Shopware is an open-source e-commerce platform primarily utilized by mid-sized enterprises to manage online storefronts and complex product catalogs. Its architecture, built on PHP and Symfony components, has historically exposed it to a range of web application vulnerabilities, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection. Recent records indicate approximately 56 Common Vulnerabilities and Exposures (CVEs), reflecting ongoing challenges with input validation and access control mechanisms. Notable incidents often stem from insecure default configurations or delayed patching of critical plugins, allowing attackers to escalate privileges or execute arbitrary code. The platform’s modular extension system further complicates security hygiene, as third-party modules may introduce unvetted code paths. Consequently, administrators must rigorously audit dependencies and apply updates promptly to mitigate risks associated with its extensive feature set and frequent codebase modifications.

CVE ID Title CVSS Severity Published
CVE-2021-32712 Information leakage in Error Handler — shopware CWE-200 5.3 Medium 2021-06-24
CVE-2021-32713 Authenticated Stored XSS — shopware CWE-79 4.8 Medium 2021-06-24
CVE-2021-32711 Leak of information via Store-API — platform CWE-200 9.1 Critical 2021-06-24
CVE-2021-32710 Potential Session Hijacking in Shopware — platform CWE-384 5.9 Medium 2021-06-24
CVE-2021-32709 Creation of order credits was not validated by acl in admin orders — platform CWE-306 4.9 Medium 2021-06-24

This page lists every published CVE security advisory associated with shopware. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.