Записи shopware
69 опубликованных записей вендора shopware.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 2,9 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 89,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-20 Improper Input Validation5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-613 Insufficient Session Expiration4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
69 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2019-12799Готовый эксплойт | In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, wshopware · shopware · CWE-502 | Высокая8,8 | — | 54,7 % | 13 июн. 2019 г. |
47В плане | CVE-2016-3109Эксплойта нет | The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.shopware · shopware · CWE-20 | Критическая9,8 | — | 28,1 % | 21 апр. 2017 г. |
40В плане | CVE-2021-37708Эксплойта нет | Command injection in mail agent settingsshopware · shopware · CWE-77 | Критическая9,8 | — | 2,4 % | 16 авг. 2021 г. |
39Наблюдать | CVE-2024-42355Эксплойта нет | Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagshopware · shopware · CWE-1336 | Критическая9,8 | — | 0,9 % | 8 авг. 2024 г. |
39Наблюдать | CVE-2023-22732Эксплойта нет | Insufficient Session Expiration in Administration in shopwareshopware · shopware · CWE-613 | Критическая9,8 | — | 0,7 % | 17 янв. 2023 г. |
39Наблюдать | CVE-2024-22406Эксплойта нет | Blind SQL-injection in DAL aggregations in Shopwareshopware · shopware · CWE-89 | Критическая9,8 | — | 0,6 % | 16 янв. 2024 г. |
39Наблюдать | CVE-2024-42357Эксплойта нет | Shopware vulnerable to blind SQL-injection in DAL aggregationsshopware · shopware · CWE-89 | Критическая9,8 | — | 0,6 % | 8 авг. 2024 г. |
36Наблюдать | CVE-2023-2017Эксплойта нет | Improper Control of Generation of Code in Twig Rendered Views in Shopwareshopware · shopware · CWE-184 | Высокая8,8 | — | 2,1 % | 17 апр. 2023 г. |
35Наблюдать | CVE-2023-22731Эксплойта нет | Improper Control of Generation of Code in Twig rendered views in shopwareshopware · shopware · CWE-94 | Высокая8,8 | — | 1,3 % | 17 янв. 2023 г. |
35Наблюдать | CVE-2020-13970Эксплойта нет | Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature.shopware · shopware · CWE-918 | Высокая8,8 | — | 1,3 % | 28 июл. 2020 г. |
35Наблюдать | CVE-2018-20713Эксплойта нет | Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.shopware · shopware · CWE-89 | Высокая8,8 | — | 1,1 % | 15 янв. 2019 г. |
35Наблюдать | CVE-2021-37711Эксплойта нет | Authenticated server-side request forgery in file upload via URL.shopware · shopware · CWE-918 | Высокая8,8 | — | 1,1 % | 16 авг. 2021 г. |
35Наблюдать | CVE-2026-31889Эксплойта нет | Shopware has a potential take over of app credentialsshopware · shopware · CWE-290 | Высокая8,9 | — | 0,4 % | 11 мар. 2026 г. |
35Наблюдать | CVE-2026-31887Эксплойта нет | Shopware unauthenticated data extraction possible through store-api.order endpointshopware · shopware · CWE-863 | Высокая8,9 | — | 0,4 % | 11 мар. 2026 г. |
34Наблюдать | CVE-2017-18357Готовый эксплойт | Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllshopware · shopware · CWE-610 | Средняя6,5 | — | 27,1 % | 15 янв. 2019 г. |
32Наблюдать | CVE-2022-24872Эксплойта нет | Improper Access Control in shopwareshopware · shopware · CWE-732 | Высокая8,1 | — | 1,1 % | 20 апр. 2022 г. |
32Наблюдать | CVE-2022-21652Эксплойта нет | Insufficient Session Expiration in shopwareshopware · shopware · CWE-613 | Высокая8,1 | — | 0,8 % | 5 янв. 2022 г. |
32Наблюдать | CVE-2024-22408Эксплойта нет | Server-Side Request Forgery (SSRF) in Shopware Flow Buildershopware · shopware · CWE-918 | Высокая8,1 | — | 0,4 % | 16 янв. 2024 г. |
31Наблюдать | CVE-2025-27892Proof of concept | Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint.shopware · shopware · CWE-89 | Средняя6,8 | — | 12,9 % | 15 апр. 2025 г. |
30Наблюдать | CVE-2020-13997Эксплойта нет | In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handlinshopware · shopware · CWE-209 | Высокая7,5 | — | 1,5 % | 28 июл. 2020 г. |
30Наблюдать | CVE-2021-32717Эксплойта нет | Private files publicly accessible with Cloud Storage providersshopware · shopware · CWE-200 | Высокая7,5 | — | 1,5 % | 24 июн. 2021 г. |
30Наблюдать | CVE-2021-32711Эксплойта нет | Leak of information via Store-APIshopware · shopware · CWE-200 | Высокая7,5 | — | 1,4 % | 24 июн. 2021 г. |
30Наблюдать | CVE-2021-37707Эксплойта нет | Manipulation of product reviews via APIshopware · shopware · CWE-20 | Высокая7,5 | — | 0,9 % | 16 авг. 2021 г. |
30Наблюдать | CVE-2021-32710Эксплойта нет | Potential Session Hijacking in Shopwareshopware · shopware · CWE-384 | Высокая7,5 | — | 0,9 % | 24 июн. 2021 г. |
30Наблюдать | CVE-2022-24892Эксплойта нет | Multiple valid tokens for password reset in Shopwareshopware · shopware · CWE-640 | Высокая7,5 | — | 0,9 % | 28 апр. 2022 г. |
- CVE-2019-1279951В плане
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, w
ВысокаяCVSS 8,8Готовый эксплойтEPSS 55 %shopware · shopware13 июн. 2019 г.
- CVE-2016-310947В плане
The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
КритическаяCVSS 9,8Эксплойта нетEPSS 28 %shopware · shopware21 апр. 2017 г.
- CVE-2021-3770840В плане
Command injection in mail agent settings
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %shopware · shopware16 авг. 2021 г.
- CVE-2024-4235539Наблюдать
Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %shopware · shopware8 авг. 2024 г.
- CVE-2023-2273239Наблюдать
Insufficient Session Expiration in Administration in shopware
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %shopware · shopware17 янв. 2023 г.
- CVE-2024-2240639Наблюдать
Blind SQL-injection in DAL aggregations in Shopware
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %shopware · shopware16 янв. 2024 г.
- CVE-2024-4235739Наблюдать
Shopware vulnerable to blind SQL-injection in DAL aggregations
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %shopware · shopware8 авг. 2024 г.
- CVE-2023-201736Наблюдать
Improper Control of Generation of Code in Twig Rendered Views in Shopware
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %shopware · shopware17 апр. 2023 г.
- CVE-2023-2273135Наблюдать
Improper Control of Generation of Code in Twig rendered views in shopware
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %shopware · shopware17 янв. 2023 г.
- CVE-2020-1397035Наблюдать
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %shopware · shopware28 июл. 2020 г.
- CVE-2018-2071335Наблюдать
Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %shopware · shopware15 янв. 2019 г.
- CVE-2021-3771135Наблюдать
Authenticated server-side request forgery in file upload via URL.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %shopware · shopware16 авг. 2021 г.
- CVE-2026-3188935Наблюдать
Shopware has a potential take over of app credentials
ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %shopware · shopware11 мар. 2026 г.
- CVE-2026-3188735Наблюдать
Shopware unauthenticated data extraction possible through store-api.order endpoint
ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %shopware · shopware11 мар. 2026 г.
- CVE-2017-1835734Наблюдать
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controll
СредняяCVSS 6,5Готовый эксплойтEPSS 27 %shopware · shopware15 янв. 2019 г.
- CVE-2022-2487232Наблюдать
Improper Access Control in shopware
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %shopware · shopware20 апр. 2022 г.
- CVE-2022-2165232Наблюдать
Insufficient Session Expiration in shopware
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %shopware · shopware5 янв. 2022 г.
- CVE-2024-2240832Наблюдать
Server-Side Request Forgery (SSRF) in Shopware Flow Builder
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %shopware · shopware16 янв. 2024 г.
- CVE-2025-2789231Наблюдать
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint.
СредняяCVSS 6,8Proof of conceptEPSS 13 %shopware · shopware15 апр. 2025 г.
- CVE-2020-1399730Наблюдать
In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handlin
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %shopware · shopware28 июл. 2020 г.
- CVE-2021-3271730Наблюдать
Private files publicly accessible with Cloud Storage providers
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %shopware · shopware24 июн. 2021 г.
- CVE-2021-3271130Наблюдать
Leak of information via Store-API
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %shopware · shopware24 июн. 2021 г.
- CVE-2021-3770730Наблюдать
Manipulation of product reviews via API
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %shopware · shopware16 авг. 2021 г.
- CVE-2021-3271030Наблюдать
Potential Session Hijacking in Shopware
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %shopware · shopware24 июн. 2021 г.
- CVE-2022-2489230Наблюдать
Multiple valid tokens for password reset in Shopware
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %shopware · shopware28 апр. 2022 г.