shopware kayıtları
shopware üreticisine ait 69 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %2,9
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %89,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-20 Improper Input Validation5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-613 Insufficient Session Expiration4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
69 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2019-12799Silahlaştırılmış | In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, wshopware · shopware · CWE-502 | Yüksek8,8 | — | %54,7 | 13 Haz 2019 |
47Planlayın | CVE-2016-3109İstismar yok | The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.shopware · shopware · CWE-20 | Kritik9,8 | — | %28,1 | 21 Nis 2017 |
40Planlayın | CVE-2021-37708İstismar yok | Command injection in mail agent settingsshopware · shopware · CWE-77 | Kritik9,8 | — | %2,4 | 16 Ağu 2021 |
39İzleyin | CVE-2024-42355İstismar yok | Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagshopware · shopware · CWE-1336 | Kritik9,8 | — | %0,9 | 8 Ağu 2024 |
39İzleyin | CVE-2023-22732İstismar yok | Insufficient Session Expiration in Administration in shopwareshopware · shopware · CWE-613 | Kritik9,8 | — | %0,7 | 17 Oca 2023 |
39İzleyin | CVE-2024-22406İstismar yok | Blind SQL-injection in DAL aggregations in Shopwareshopware · shopware · CWE-89 | Kritik9,8 | — | %0,6 | 16 Oca 2024 |
39İzleyin | CVE-2024-42357İstismar yok | Shopware vulnerable to blind SQL-injection in DAL aggregationsshopware · shopware · CWE-89 | Kritik9,8 | — | %0,6 | 8 Ağu 2024 |
36İzleyin | CVE-2023-2017İstismar yok | Improper Control of Generation of Code in Twig Rendered Views in Shopwareshopware · shopware · CWE-184 | Yüksek8,8 | — | %2,1 | 17 Nis 2023 |
35İzleyin | CVE-2023-22731İstismar yok | Improper Control of Generation of Code in Twig rendered views in shopwareshopware · shopware · CWE-94 | Yüksek8,8 | — | %1,3 | 17 Oca 2023 |
35İzleyin | CVE-2020-13970İstismar yok | Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature.shopware · shopware · CWE-918 | Yüksek8,8 | — | %1,3 | 28 Tem 2020 |
35İzleyin | CVE-2018-20713İstismar yok | Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.shopware · shopware · CWE-89 | Yüksek8,8 | — | %1,1 | 15 Oca 2019 |
35İzleyin | CVE-2021-37711İstismar yok | Authenticated server-side request forgery in file upload via URL.shopware · shopware · CWE-918 | Yüksek8,8 | — | %1,1 | 16 Ağu 2021 |
35İzleyin | CVE-2026-31889İstismar yok | Shopware has a potential take over of app credentialsshopware · shopware · CWE-290 | Yüksek8,9 | — | %0,4 | 11 Mar 2026 |
35İzleyin | CVE-2026-31887İstismar yok | Shopware unauthenticated data extraction possible through store-api.order endpointshopware · shopware · CWE-863 | Yüksek8,9 | — | %0,4 | 11 Mar 2026 |
34İzleyin | CVE-2017-18357Silahlaştırılmış | Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllshopware · shopware · CWE-610 | Orta6,5 | — | %27,1 | 15 Oca 2019 |
32İzleyin | CVE-2022-24872İstismar yok | Improper Access Control in shopwareshopware · shopware · CWE-732 | Yüksek8,1 | — | %1,1 | 20 Nis 2022 |
32İzleyin | CVE-2022-21652İstismar yok | Insufficient Session Expiration in shopwareshopware · shopware · CWE-613 | Yüksek8,1 | — | %0,8 | 5 Oca 2022 |
32İzleyin | CVE-2024-22408İstismar yok | Server-Side Request Forgery (SSRF) in Shopware Flow Buildershopware · shopware · CWE-918 | Yüksek8,1 | — | %0,4 | 16 Oca 2024 |
31İzleyin | CVE-2025-27892Kavram kanıtı | Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint.shopware · shopware · CWE-89 | Orta6,8 | — | %12,9 | 15 Nis 2025 |
30İzleyin | CVE-2020-13997İstismar yok | In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handlinshopware · shopware · CWE-209 | Yüksek7,5 | — | %1,5 | 28 Tem 2020 |
30İzleyin | CVE-2021-32717İstismar yok | Private files publicly accessible with Cloud Storage providersshopware · shopware · CWE-200 | Yüksek7,5 | — | %1,5 | 24 Haz 2021 |
30İzleyin | CVE-2021-32711İstismar yok | Leak of information via Store-APIshopware · shopware · CWE-200 | Yüksek7,5 | — | %1,4 | 24 Haz 2021 |
30İzleyin | CVE-2021-37707İstismar yok | Manipulation of product reviews via APIshopware · shopware · CWE-20 | Yüksek7,5 | — | %0,9 | 16 Ağu 2021 |
30İzleyin | CVE-2021-32710İstismar yok | Potential Session Hijacking in Shopwareshopware · shopware · CWE-384 | Yüksek7,5 | — | %0,9 | 24 Haz 2021 |
30İzleyin | CVE-2022-24892İstismar yok | Multiple valid tokens for password reset in Shopwareshopware · shopware · CWE-640 | Yüksek7,5 | — | %0,9 | 28 Nis 2022 |
- CVE-2019-1279951Planlayın
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, w
YüksekCVSS 8,8SilahlaştırılmışEPSS %55shopware · shopware13 Haz 2019
- CVE-2016-310947Planlayın
The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
KritikCVSS 9,8İstismar yokEPSS %28shopware · shopware21 Nis 2017
- CVE-2021-3770840Planlayın
Command injection in mail agent settings
KritikCVSS 9,8İstismar yokEPSS %2shopware · shopware16 Ağu 2021
- CVE-2024-4235539İzleyin
Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
KritikCVSS 9,8İstismar yokEPSS %1shopware · shopware8 Ağu 2024
- CVE-2023-2273239İzleyin
Insufficient Session Expiration in Administration in shopware
KritikCVSS 9,8İstismar yokEPSS %1shopware · shopware17 Oca 2023
- CVE-2024-2240639İzleyin
Blind SQL-injection in DAL aggregations in Shopware
KritikCVSS 9,8İstismar yokEPSS %1shopware · shopware16 Oca 2024
- CVE-2024-4235739İzleyin
Shopware vulnerable to blind SQL-injection in DAL aggregations
KritikCVSS 9,8İstismar yokEPSS %1shopware · shopware8 Ağu 2024
- CVE-2023-201736İzleyin
Improper Control of Generation of Code in Twig Rendered Views in Shopware
YüksekCVSS 8,8İstismar yokEPSS %2shopware · shopware17 Nis 2023
- CVE-2023-2273135İzleyin
Improper Control of Generation of Code in Twig rendered views in shopware
YüksekCVSS 8,8İstismar yokEPSS %1shopware · shopware17 Oca 2023
- CVE-2020-1397035İzleyin
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature.
YüksekCVSS 8,8İstismar yokEPSS %1shopware · shopware28 Tem 2020
- CVE-2018-2071335İzleyin
Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.
YüksekCVSS 8,8İstismar yokEPSS %1shopware · shopware15 Oca 2019
- CVE-2021-3771135İzleyin
Authenticated server-side request forgery in file upload via URL.
YüksekCVSS 8,8İstismar yokEPSS %1shopware · shopware16 Ağu 2021
- CVE-2026-3188935İzleyin
Shopware has a potential take over of app credentials
YüksekCVSS 8,9İstismar yokEPSS %0shopware · shopware11 Mar 2026
- CVE-2026-3188735İzleyin
Shopware unauthenticated data extraction possible through store-api.order endpoint
YüksekCVSS 8,9İstismar yokEPSS %0shopware · shopware11 Mar 2026
- CVE-2017-1835734İzleyin
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controll
OrtaCVSS 6,5SilahlaştırılmışEPSS %27shopware · shopware15 Oca 2019
- CVE-2022-2487232İzleyin
Improper Access Control in shopware
YüksekCVSS 8,1İstismar yokEPSS %1shopware · shopware20 Nis 2022
- CVE-2022-2165232İzleyin
Insufficient Session Expiration in shopware
YüksekCVSS 8,1İstismar yokEPSS %1shopware · shopware5 Oca 2022
- CVE-2024-2240832İzleyin
Server-Side Request Forgery (SSRF) in Shopware Flow Builder
YüksekCVSS 8,1İstismar yokEPSS %0shopware · shopware16 Oca 2024
- CVE-2025-2789231İzleyin
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint.
OrtaCVSS 6,8Kavram kanıtıEPSS %13shopware · shopware15 Nis 2025
- CVE-2020-1399730İzleyin
In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handlin
YüksekCVSS 7,5İstismar yokEPSS %1shopware · shopware28 Tem 2020
- CVE-2021-3271730İzleyin
Private files publicly accessible with Cloud Storage providers
YüksekCVSS 7,5İstismar yokEPSS %1shopware · shopware24 Haz 2021
- CVE-2021-3271130İzleyin
Leak of information via Store-API
YüksekCVSS 7,5İstismar yokEPSS %1shopware · shopware24 Haz 2021
- CVE-2021-3770730İzleyin
Manipulation of product reviews via API
YüksekCVSS 7,5İstismar yokEPSS %1shopware · shopware16 Ağu 2021
- CVE-2021-3271030İzleyin
Potential Session Hijacking in Shopware
YüksekCVSS 7,5İstismar yokEPSS %1shopware · shopware24 Haz 2021
- CVE-2022-2489230İzleyin
Multiple valid tokens for password reset in Shopware
YüksekCVSS 7,5İstismar yokEPSS %1shopware · shopware28 Nis 2022