İçeriğe atla
Noroxi

shopware kayıtları

shopware üreticisine ait 69 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
2 · %2,9
Pre-auth RCE
4
Düzeltme kaydı olan
%89,9
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

69 kayıt
  • CVE-2019-12799
    51Planlayın

    In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, w

    YüksekCVSS 8,8SilahlaştırılmışEPSS %55

    shopware · shopware13 Haz 2019

  • CVE-2016-3109
    47Planlayın

    The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.

    KritikCVSS 9,8İstismar yokEPSS %28

    shopware · shopware21 Nis 2017

  • CVE-2021-37708
    40Planlayın

    Command injection in mail agent settings

    KritikCVSS 9,8İstismar yokEPSS %2

    shopware · shopware16 Ağu 2021

  • CVE-2024-42355
    39İzleyin

    Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

    KritikCVSS 9,8İstismar yokEPSS %1

    shopware · shopware8 Ağu 2024

  • CVE-2023-22732
    39İzleyin

    Insufficient Session Expiration in Administration in shopware

    KritikCVSS 9,8İstismar yokEPSS %1

    shopware · shopware17 Oca 2023

  • CVE-2024-22406
    39İzleyin

    Blind SQL-injection in DAL aggregations in Shopware

    KritikCVSS 9,8İstismar yokEPSS %1

    shopware · shopware16 Oca 2024

  • CVE-2024-42357
    39İzleyin

    Shopware vulnerable to blind SQL-injection in DAL aggregations

    KritikCVSS 9,8İstismar yokEPSS %1

    shopware · shopware8 Ağu 2024

  • CVE-2023-2017
    36İzleyin

    Improper Control of Generation of Code in Twig Rendered Views in Shopware

    YüksekCVSS 8,8İstismar yokEPSS %2

    shopware · shopware17 Nis 2023

  • CVE-2023-22731
    35İzleyin

    Improper Control of Generation of Code in Twig rendered views in shopware

    YüksekCVSS 8,8İstismar yokEPSS %1

    shopware · shopware17 Oca 2023

  • CVE-2020-13970
    35İzleyin

    Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature.

    YüksekCVSS 8,8İstismar yokEPSS %1

    shopware · shopware28 Tem 2020

  • CVE-2018-20713
    35İzleyin

    Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.

    YüksekCVSS 8,8İstismar yokEPSS %1

    shopware · shopware15 Oca 2019

  • CVE-2021-37711
    35İzleyin

    Authenticated server-side request forgery in file upload via URL.

    YüksekCVSS 8,8İstismar yokEPSS %1

    shopware · shopware16 Ağu 2021

  • CVE-2026-31889
    35İzleyin

    Shopware has a potential take over of app credentials

    YüksekCVSS 8,9İstismar yokEPSS %0

    shopware · shopware11 Mar 2026

  • CVE-2026-31887
    35İzleyin

    Shopware unauthenticated data extraction possible through store-api.order endpoint

    YüksekCVSS 8,9İstismar yokEPSS %0

    shopware · shopware11 Mar 2026

  • CVE-2017-18357
    34İzleyin

    Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controll

    OrtaCVSS 6,5SilahlaştırılmışEPSS %27

    shopware · shopware15 Oca 2019

  • CVE-2022-24872
    32İzleyin

    Improper Access Control in shopware

    YüksekCVSS 8,1İstismar yokEPSS %1

    shopware · shopware20 Nis 2022

  • CVE-2022-21652
    32İzleyin

    Insufficient Session Expiration in shopware

    YüksekCVSS 8,1İstismar yokEPSS %1

    shopware · shopware5 Oca 2022

  • CVE-2024-22408
    32İzleyin

    Server-Side Request Forgery (SSRF) in Shopware Flow Builder

    YüksekCVSS 8,1İstismar yokEPSS %0

    shopware · shopware16 Oca 2024

  • CVE-2025-27892
    31İzleyin

    Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint.

    OrtaCVSS 6,8Kavram kanıtıEPSS %13

    shopware · shopware15 Nis 2025

  • CVE-2020-13997
    30İzleyin

    In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handlin

    YüksekCVSS 7,5İstismar yokEPSS %1

    shopware · shopware28 Tem 2020

  • CVE-2021-32717
    30İzleyin

    Private files publicly accessible with Cloud Storage providers

    YüksekCVSS 7,5İstismar yokEPSS %1

    shopware · shopware24 Haz 2021

  • CVE-2021-32711
    30İzleyin

    Leak of information via Store-API

    YüksekCVSS 7,5İstismar yokEPSS %1

    shopware · shopware24 Haz 2021

  • CVE-2021-37707
    30İzleyin

    Manipulation of product reviews via API

    YüksekCVSS 7,5İstismar yokEPSS %1

    shopware · shopware16 Ağu 2021

  • CVE-2021-32710
    30İzleyin

    Potential Session Hijacking in Shopware

    YüksekCVSS 7,5İstismar yokEPSS %1

    shopware · shopware24 Haz 2021

  • CVE-2022-24892
    30İzleyin

    Multiple valid tokens for password reset in Shopware

    YüksekCVSS 7,5İstismar yokEPSS %1

    shopware · shopware28 Nis 2022