shopware records
69 published records for vendor shopware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 2.9%
- Pre-auth RCE
- 4
- With a fix record
- 89.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-20 Improper Input Validation5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-613 Insufficient Session Expiration4
The weakness classes this vendor ships most often: where to look.
CWEAll records
69 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2019-12799Weaponized | In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, wshopware · shopware · CWE-502 | High8.8 | — | 54.7% | Jun 13, 2019 |
47Plan | CVE-2016-3109No exploit | The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.shopware · shopware · CWE-20 | Critical9.8 | — | 28.1% | Apr 21, 2017 |
40Plan | CVE-2021-37708No exploit | Command injection in mail agent settingsshopware · shopware · CWE-77 | Critical9.8 | — | 2.4% | Aug 16, 2021 |
39Monitor | CVE-2024-42355No exploit | Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagshopware · shopware · CWE-1336 | Critical9.8 | — | 0.9% | Aug 8, 2024 |
39Monitor | CVE-2023-22732No exploit | Insufficient Session Expiration in Administration in shopwareshopware · shopware · CWE-613 | Critical9.8 | — | 0.7% | Jan 17, 2023 |
39Monitor | CVE-2024-22406No exploit | Blind SQL-injection in DAL aggregations in Shopwareshopware · shopware · CWE-89 | Critical9.8 | — | 0.6% | Jan 16, 2024 |
39Monitor | CVE-2024-42357No exploit | Shopware vulnerable to blind SQL-injection in DAL aggregationsshopware · shopware · CWE-89 | Critical9.8 | — | 0.6% | Aug 8, 2024 |
36Monitor | CVE-2023-2017No exploit | Improper Control of Generation of Code in Twig Rendered Views in Shopwareshopware · shopware · CWE-184 | High8.8 | — | 2.1% | Apr 17, 2023 |
35Monitor | CVE-2023-22731No exploit | Improper Control of Generation of Code in Twig rendered views in shopwareshopware · shopware · CWE-94 | High8.8 | — | 1.3% | Jan 17, 2023 |
35Monitor | CVE-2020-13970No exploit | Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature.shopware · shopware · CWE-918 | High8.8 | — | 1.3% | Jul 28, 2020 |
35Monitor | CVE-2018-20713No exploit | Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.shopware · shopware · CWE-89 | High8.8 | — | 1.1% | Jan 15, 2019 |
35Monitor | CVE-2021-37711No exploit | Authenticated server-side request forgery in file upload via URL.shopware · shopware · CWE-918 | High8.8 | — | 1.1% | Aug 16, 2021 |
35Monitor | CVE-2026-31889No exploit | Shopware has a potential take over of app credentialsshopware · shopware · CWE-290 | High8.9 | — | 0.4% | Mar 11, 2026 |
35Monitor | CVE-2026-31887No exploit | Shopware unauthenticated data extraction possible through store-api.order endpointshopware · shopware · CWE-863 | High8.9 | — | 0.4% | Mar 11, 2026 |
34Monitor | CVE-2017-18357Weaponized | Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllshopware · shopware · CWE-610 | Medium6.5 | — | 27.1% | Jan 15, 2019 |
32Monitor | CVE-2022-24872No exploit | Improper Access Control in shopwareshopware · shopware · CWE-732 | High8.1 | — | 1.1% | Apr 20, 2022 |
32Monitor | CVE-2022-21652No exploit | Insufficient Session Expiration in shopwareshopware · shopware · CWE-613 | High8.1 | — | 0.8% | Jan 5, 2022 |
32Monitor | CVE-2024-22408No exploit | Server-Side Request Forgery (SSRF) in Shopware Flow Buildershopware · shopware · CWE-918 | High8.1 | — | 0.4% | Jan 16, 2024 |
31Monitor | CVE-2025-27892Proof of concept | Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint.shopware · shopware · CWE-89 | Medium6.8 | — | 12.9% | Apr 15, 2025 |
30Monitor | CVE-2020-13997No exploit | In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handlinshopware · shopware · CWE-209 | High7.5 | — | 1.5% | Jul 28, 2020 |
30Monitor | CVE-2021-32717No exploit | Private files publicly accessible with Cloud Storage providersshopware · shopware · CWE-200 | High7.5 | — | 1.5% | Jun 24, 2021 |
30Monitor | CVE-2021-32711No exploit | Leak of information via Store-APIshopware · shopware · CWE-200 | High7.5 | — | 1.4% | Jun 24, 2021 |
30Monitor | CVE-2021-37707No exploit | Manipulation of product reviews via APIshopware · shopware · CWE-20 | High7.5 | — | 0.9% | Aug 16, 2021 |
30Monitor | CVE-2021-32710No exploit | Potential Session Hijacking in Shopwareshopware · shopware · CWE-384 | High7.5 | — | 0.9% | Jun 24, 2021 |
30Monitor | CVE-2022-24892No exploit | Multiple valid tokens for password reset in Shopwareshopware · shopware · CWE-640 | High7.5 | — | 0.9% | Apr 28, 2022 |
- CVE-2019-1279951Plan
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, w
HighCVSS 8.8WeaponizedEPSS 55%shopware · shopwareJun 13, 2019
- CVE-2016-310947Plan
The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
CriticalCVSS 9.8No exploitEPSS 28%shopware · shopwareApr 21, 2017
- CVE-2021-3770840Plan
Command injection in mail agent settings
CriticalCVSS 9.8No exploitEPSS 2%shopware · shopwareAug 16, 2021
- CVE-2024-4235539Monitor
Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
CriticalCVSS 9.8No exploitEPSS 1%shopware · shopwareAug 8, 2024
- CVE-2023-2273239Monitor
Insufficient Session Expiration in Administration in shopware
CriticalCVSS 9.8No exploitEPSS 1%shopware · shopwareJan 17, 2023
- CVE-2024-2240639Monitor
Blind SQL-injection in DAL aggregations in Shopware
CriticalCVSS 9.8No exploitEPSS 1%shopware · shopwareJan 16, 2024
- CVE-2024-4235739Monitor
Shopware vulnerable to blind SQL-injection in DAL aggregations
CriticalCVSS 9.8No exploitEPSS 1%shopware · shopwareAug 8, 2024
- CVE-2023-201736Monitor
Improper Control of Generation of Code in Twig Rendered Views in Shopware
HighCVSS 8.8No exploitEPSS 2%shopware · shopwareApr 17, 2023
- CVE-2023-2273135Monitor
Improper Control of Generation of Code in Twig rendered views in shopware
HighCVSS 8.8No exploitEPSS 1%shopware · shopwareJan 17, 2023
- CVE-2020-1397035Monitor
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature.
HighCVSS 8.8No exploitEPSS 1%shopware · shopwareJul 28, 2020
- CVE-2018-2071335Monitor
Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.
HighCVSS 8.8No exploitEPSS 1%shopware · shopwareJan 15, 2019
- CVE-2021-3771135Monitor
Authenticated server-side request forgery in file upload via URL.
HighCVSS 8.8No exploitEPSS 1%shopware · shopwareAug 16, 2021
- CVE-2026-3188935Monitor
Shopware has a potential take over of app credentials
HighCVSS 8.9No exploitEPSS 0%shopware · shopwareMar 11, 2026
- CVE-2026-3188735Monitor
Shopware unauthenticated data extraction possible through store-api.order endpoint
HighCVSS 8.9No exploitEPSS 0%shopware · shopwareMar 11, 2026
- CVE-2017-1835734Monitor
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controll
MediumCVSS 6.5WeaponizedEPSS 27%shopware · shopwareJan 15, 2019
- CVE-2022-2487232Monitor
Improper Access Control in shopware
HighCVSS 8.1No exploitEPSS 1%shopware · shopwareApr 20, 2022
- CVE-2022-2165232Monitor
Insufficient Session Expiration in shopware
HighCVSS 8.1No exploitEPSS 1%shopware · shopwareJan 5, 2022
- CVE-2024-2240832Monitor
Server-Side Request Forgery (SSRF) in Shopware Flow Builder
HighCVSS 8.1No exploitEPSS 0%shopware · shopwareJan 16, 2024
- CVE-2025-2789231Monitor
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint.
MediumCVSS 6.8Proof of conceptEPSS 13%shopware · shopwareApr 15, 2025
- CVE-2020-1399730Monitor
In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handlin
HighCVSS 7.5No exploitEPSS 1%shopware · shopwareJul 28, 2020
- CVE-2021-3271730Monitor
Private files publicly accessible with Cloud Storage providers
HighCVSS 7.5No exploitEPSS 1%shopware · shopwareJun 24, 2021
- CVE-2021-3271130Monitor
Leak of information via Store-API
HighCVSS 7.5No exploitEPSS 1%shopware · shopwareJun 24, 2021
- CVE-2021-3770730Monitor
Manipulation of product reviews via API
HighCVSS 7.5No exploitEPSS 1%shopware · shopwareAug 16, 2021
- CVE-2021-3271030Monitor
Potential Session Hijacking in Shopware
HighCVSS 7.5No exploitEPSS 1%shopware · shopwareJun 24, 2021
- CVE-2022-2489230Monitor
Multiple valid tokens for password reset in Shopware
HighCVSS 7.5No exploitEPSS 1%shopware · shopwareApr 28, 2022