Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

shopware — Vulnerabilities & Security Advisories 65

Browse all 65 CVE security advisories affecting shopware. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Shopware is an open-source e-commerce platform primarily utilized by mid-sized enterprises to manage online storefronts and complex product catalogs. Its architecture, built on PHP and Symfony components, has historically exposed it to a range of web application vulnerabilities, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection. Recent records indicate approximately 56 Common Vulnerabilities and Exposures (CVEs), reflecting ongoing challenges with input validation and access control mechanisms. Notable incidents often stem from insecure default configurations or delayed patching of critical plugins, allowing attackers to escalate privileges or execute arbitrary code. The platform’s modular extension system further complicates security hygiene, as third-party modules may introduce unvetted code paths. Consequently, administrators must rigorously audit dependencies and apply updates promptly to mitigate risks associated with its extensive feature set and frequent codebase modifications.

Found 1 results / 65Clear Filters
High2026-07-24
Shopware SSO referer trust leading to an arbitrary redirect target · Advisory · shopware/shopware · GitHub
Medium2026-07-24
SSRF in Media External-Link Endpoint Bypasses IP Validation · Advisory · shopware/shopware · GitHub
MediumCVE-2020-480152026-07-18
Stored XSS via SVG file upload — no SVG sanitization · Advisory · shopware/shopware · GitHub
Medium2026-07-18
fix: handle payment route order customer filtering · shopware/shopware@69dd5b6 · GitHub
High2026-07-18
fix: handle payment route order customer filtering · shopware/shopware@df15f2e · GitHub
High2026-07-18
Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment · Advisory · shopware/shopware · GitHub
MediumCVE-2024-480142026-07-18
Admin API ACL Bypass in Order State Transition Endpoints · Advisory · shopware/shopware · GitHub
High2026-07-18
fix: acl permissions on state transition updates · shopware/shopware@86dff24 · GitHub
High2026-07-18
fix: acl permissions on state transition updates · shopware/shopware@9f15fae · GitHub
High2026-07-18
fix: ApiAware flag is removed from user hash backport 6.6.x · shopware/shopware@06f8b9a · GitHub
Critical2026-07-18
fix: Prevent acl admin escalation · shopware/shopware@7f1cef3 · GitHub
Critical2026-07-18
fix: Prevent integration admin escalation via Sync API · shopware/shopware@1e047f6 · GitHub
HighCVE-2024-49082026-07-18
Privilege Escalation via Sync API Integration Admin Flag Bypass · Advisory · shopware/shopware · GitHub
HighCVE-2024-480102026-07-18
Privilege escalation: non-admin user with user:create ACL can create admin accounts · Advisory · shopware/shopware · Git
High2026-07-18
fix: Prevent acl admin escalation · shopware/shopware@d8d9a34 · GitHub
High2026-05-30
fix(security): authorization bypass and discount race in cart/checkout by mckenziearts · Pull Request #511 · shopperlabs
LowCVE-2026-258782026-02-10
Adminer UI is accessible without admin session · Advisory · FriendsOfShopware/FroshPlatformAdminer · GitHub
HighCVE-2026-234982026-01-20
Improper Control of Generation of Code in Twig rendered views · Advisory · shopware/shopware · GitHub
LowCVE-2025-301502025-04-09
Check for registered accounts through the store-api · Advisory · shopware/shopware · GitHub
MediumCVE-2024-423542024-08-10
Improper Access Control with ManyToMany associations in store-api · Advisory · shopware/shopware · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with shopware. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.