Перейти к содержимому
Noroxi

Записи shopware

69 опубликованных записей вендора shopware.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
2 · 2,9 %
Pre-auth RCE
4
С записью об исправлении
89,9 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

69 записей
  • CVE-2019-12799
    51В плане

    In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, w

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 55 %

    shopware · shopware13 июн. 2019 г.

  • CVE-2016-3109
    47В плане

    The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.

    КритическаяCVSS 9,8Эксплойта нетEPSS 28 %

    shopware · shopware21 апр. 2017 г.

  • CVE-2021-37708
    40В плане

    Command injection in mail agent settings

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    shopware · shopware16 авг. 2021 г.

  • CVE-2024-42355
    39Наблюдать

    Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    shopware · shopware8 авг. 2024 г.

  • CVE-2023-22732
    39Наблюдать

    Insufficient Session Expiration in Administration in shopware

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    shopware · shopware17 янв. 2023 г.

  • CVE-2024-22406
    39Наблюдать

    Blind SQL-injection in DAL aggregations in Shopware

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    shopware · shopware16 янв. 2024 г.

  • CVE-2024-42357
    39Наблюдать

    Shopware vulnerable to blind SQL-injection in DAL aggregations

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    shopware · shopware8 авг. 2024 г.

  • CVE-2023-2017
    36Наблюдать

    Improper Control of Generation of Code in Twig Rendered Views in Shopware

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    shopware · shopware17 апр. 2023 г.

  • CVE-2023-22731
    35Наблюдать

    Improper Control of Generation of Code in Twig rendered views in shopware

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    shopware · shopware17 янв. 2023 г.

  • CVE-2020-13970
    35Наблюдать

    Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    shopware · shopware28 июл. 2020 г.

  • CVE-2018-20713
    35Наблюдать

    Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    shopware · shopware15 янв. 2019 г.

  • CVE-2021-37711
    35Наблюдать

    Authenticated server-side request forgery in file upload via URL.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    shopware · shopware16 авг. 2021 г.

  • CVE-2026-31889
    35Наблюдать

    Shopware has a potential take over of app credentials

    ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %

    shopware · shopware11 мар. 2026 г.

  • CVE-2026-31887
    35Наблюдать

    Shopware unauthenticated data extraction possible through store-api.order endpoint

    ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %

    shopware · shopware11 мар. 2026 г.

  • CVE-2017-18357
    34Наблюдать

    Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controll

    СредняяCVSS 6,5Готовый эксплойтEPSS 27 %

    shopware · shopware15 янв. 2019 г.

  • CVE-2022-24872
    32Наблюдать

    Improper Access Control in shopware

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    shopware · shopware20 апр. 2022 г.

  • CVE-2022-21652
    32Наблюдать

    Insufficient Session Expiration in shopware

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    shopware · shopware5 янв. 2022 г.

  • CVE-2024-22408
    32Наблюдать

    Server-Side Request Forgery (SSRF) in Shopware Flow Builder

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    shopware · shopware16 янв. 2024 г.

  • CVE-2025-27892
    31Наблюдать

    Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint.

    СредняяCVSS 6,8Proof of conceptEPSS 13 %

    shopware · shopware15 апр. 2025 г.

  • CVE-2020-13997
    30Наблюдать

    In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handlin

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    shopware · shopware28 июл. 2020 г.

  • CVE-2021-32717
    30Наблюдать

    Private files publicly accessible with Cloud Storage providers

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    shopware · shopware24 июн. 2021 г.

  • CVE-2021-32711
    30Наблюдать

    Leak of information via Store-API

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    shopware · shopware24 июн. 2021 г.

  • CVE-2021-37707
    30Наблюдать

    Manipulation of product reviews via API

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    shopware · shopware16 авг. 2021 г.

  • CVE-2021-32710
    30Наблюдать

    Potential Session Hijacking in Shopware

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    shopware · shopware24 июн. 2021 г.

  • CVE-2022-24892
    30Наблюдать

    Multiple valid tokens for password reset in Shopware

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    shopware · shopware28 апр. 2022 г.