Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

shopware — Vulnerabilities & Security Advisories 65

Browse all 65 CVE security advisories affecting shopware. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Shopware is an open-source e-commerce platform primarily utilized by mid-sized enterprises to manage online storefronts and complex product catalogs. Its architecture, built on PHP and Symfony components, has historically exposed it to a range of web application vulnerabilities, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection. Recent records indicate approximately 56 Common Vulnerabilities and Exposures (CVEs), reflecting ongoing challenges with input validation and access control mechanisms. Notable incidents often stem from insecure default configurations or delayed patching of critical plugins, allowing attackers to escalate privileges or execute arbitrary code. The platform’s modular extension system further complicates security hygiene, as third-party modules may introduce unvetted code paths. Consequently, administrators must rigorously audit dependencies and apply updates promptly to mitigate risks associated with its extensive feature set and frequent codebase modifications.

Found 22 results / 65 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2023-22733 Improper Output Neutralization in Log Module in shopware — platform CWE-532 2.7 Low 2023-01-17
CVE-2023-22732 Insufficient Session Expiration in Administration in shopware — platform CWE-613 3.7 Low 2023-01-17
CVE-2023-22731 Improper Control of Generation of Code in Twig rendered views in shopware — platform CWE-94 10.0 Critical 2023-01-17
CVE-2023-22730 Improper Input Validation of Clearance sale in cart — platform CWE-20 5.3 Medium 2023-01-17
CVE-2023-22734 Improper Input Newsletter subscription option validation in shopware — platform CWE-20 4.3 Medium 2023-01-17
CVE-2022-24872 Improper Access Control in shopware — platform CWE-732 8.1 High 2022-04-20
CVE-2022-24871 Server-Side Request Forgery (SSRF) in Shopware — platform CWE-918 7.2 High 2022-04-20
CVE-2022-24744 Insufficient Session Expiration in shopware — platform CWE-613 2.6 Low 2022-03-09
CVE-2022-24745 Guest session is shared between customers in shopware — platform CWE-384 4.8 Medium 2022-03-09
CVE-2022-24746 HTML injection possibility in voucher code form — platform CWE-79 6.1 Medium 2022-03-09
CVE-2022-24747 HTTP caching is marking private HTTP headers as public — platform CWE-200 6.3 Medium 2022-03-09
CVE-2022-24748 Incorrect Authentication in shopware — platform CWE-287 6.8 Medium 2022-03-09
CVE-2021-37711 Authenticated server-side request forgery in file upload via URL. — platform CWE-918 8.8 High 2021-08-16
CVE-2021-37710 Cross-Site Scripting via SVG media files — platform CWE-79 8.0 High 2021-08-16
CVE-2021-37709 Insecure direct object reference of log files of the Import/Export feature — platform CWE-532 6.5 Medium 2021-08-16
CVE-2021-37708 Command injection in mail agent settings — platform CWE-77 8.8 High 2021-08-16
CVE-2021-37707 Manipulation of product reviews via API — platform CWE-20 6.5 Medium 2021-08-16
CVE-2021-32717 Private files publicly accessible with Cloud Storage providers — platform CWE-200 7.5 High 2021-06-24
CVE-2021-32716 Internal hidden fields are visible on to many associations in admin api — platform CWE-200 4.4 Medium 2021-06-24
CVE-2021-32711 Leak of information via Store-API — platform CWE-200 9.1 Critical 2021-06-24
CVE-2021-32710 Potential Session Hijacking in Shopware — platform CWE-384 5.9 Medium 2021-06-24
CVE-2021-32709 Creation of order credits was not validated by acl in admin orders — platform CWE-306 4.9 Medium 2021-06-24

This page lists every published CVE security advisory associated with shopware. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.