Skip to content
Noroxi

shopware records

69 published records for vendor shopware.

All records

69 records
  • In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, w

    HighCVSS 8.8WeaponizedEPSS 55%

    shopware · shopwareJun 13, 2019

  • The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.

    CriticalCVSS 9.8No exploitEPSS 28%

    shopware · shopwareApr 21, 2017

  • Command injection in mail agent settings

    CriticalCVSS 9.8No exploitEPSS 2%

    shopware · shopwareAug 16, 2021

  • Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

    CriticalCVSS 9.8No exploitEPSS 1%

    shopware · shopwareAug 8, 2024

  • Insufficient Session Expiration in Administration in shopware

    CriticalCVSS 9.8No exploitEPSS 1%

    shopware · shopwareJan 17, 2023

  • Blind SQL-injection in DAL aggregations in Shopware

    CriticalCVSS 9.8No exploitEPSS 1%

    shopware · shopwareJan 16, 2024

  • Shopware vulnerable to blind SQL-injection in DAL aggregations

    CriticalCVSS 9.8No exploitEPSS 1%

    shopware · shopwareAug 8, 2024

  • CVE-2023-2017
    36Monitor

    Improper Control of Generation of Code in Twig Rendered Views in Shopware

    HighCVSS 8.8No exploitEPSS 2%

    shopware · shopwareApr 17, 2023

  • Improper Control of Generation of Code in Twig rendered views in shopware

    HighCVSS 8.8No exploitEPSS 1%

    shopware · shopwareJan 17, 2023

  • Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature.

    HighCVSS 8.8No exploitEPSS 1%

    shopware · shopwareJul 28, 2020

  • Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.

    HighCVSS 8.8No exploitEPSS 1%

    shopware · shopwareJan 15, 2019

  • Authenticated server-side request forgery in file upload via URL.

    HighCVSS 8.8No exploitEPSS 1%

    shopware · shopwareAug 16, 2021

  • Shopware has a potential take over of app credentials

    HighCVSS 8.9No exploitEPSS 0%

    shopware · shopwareMar 11, 2026

  • Shopware unauthenticated data extraction possible through store-api.order endpoint

    HighCVSS 8.9No exploitEPSS 0%

    shopware · shopwareMar 11, 2026

  • Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controll

    MediumCVSS 6.5WeaponizedEPSS 27%

    shopware · shopwareJan 15, 2019

  • Improper Access Control in shopware

    HighCVSS 8.1No exploitEPSS 1%

    shopware · shopwareApr 20, 2022

  • Insufficient Session Expiration in shopware

    HighCVSS 8.1No exploitEPSS 1%

    shopware · shopwareJan 5, 2022

  • Server-Side Request Forgery (SSRF) in Shopware Flow Builder

    HighCVSS 8.1No exploitEPSS 0%

    shopware · shopwareJan 16, 2024

  • Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint.

    MediumCVSS 6.8Proof of conceptEPSS 13%

    shopware · shopwareApr 15, 2025

  • In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handlin

    HighCVSS 7.5No exploitEPSS 1%

    shopware · shopwareJul 28, 2020

  • Private files publicly accessible with Cloud Storage providers

    HighCVSS 7.5No exploitEPSS 1%

    shopware · shopwareJun 24, 2021

  • Leak of information via Store-API

    HighCVSS 7.5No exploitEPSS 1%

    shopware · shopwareJun 24, 2021

  • Manipulation of product reviews via API

    HighCVSS 7.5No exploitEPSS 1%

    shopware · shopwareAug 16, 2021

  • Potential Session Hijacking in Shopware

    HighCVSS 7.5No exploitEPSS 1%

    shopware · shopwareJun 24, 2021

  • Multiple valid tokens for password reset in Shopware

    HighCVSS 7.5No exploitEPSS 1%

    shopware · shopwareApr 28, 2022