Shopware / Platform
33 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-48012 | Shopware SSO referer trust leading to an arbitrary redirect target | MEDIUM | 4.3 | Jul 23, 2026 |
| CVE-2026-48013 | Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation | MEDIUM | 4.1 | Jul 23, 2026 |
| CVE-2026-48009 | Shopware: Admin Account Takeover via User Recovery Hash Exposure | MEDIUM | 6.8 | Jul 17, 2026 |
| CVE-2026-48014 | Shopware: Admin API ACL Bypass in Order State Transition Endpoints | MEDIUM | 6.5 | Jul 17, 2026 |
| CVE-2026-48010 | Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts | MEDIUM | 6.5 | Jul 17, 2026 |
| CVE-2026-48016 | Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment | MEDIUM | 4.3 | Jul 17, 2026 |
| CVE-2026-48015 | Shopware: Stored XSS via SVG file upload — no SVG sanitization | MEDIUM | 4.9 | Jul 17, 2026 |
| CVE-2026-48008 | Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass | MEDIUM | 6.5 | Jul 17, 2026 |
| CVE-2026-31889 | Shopware has a potential take over of app credentials | HIGH | 8.9 | Mar 11, 2026 |
| CVE-2026-31888 | Shopware has user enumeration via distinct error codes on Store API login endpoint | MEDIUM | 5.3 | Mar 11, 2026 |
| CVE-2026-31887 | Shopware unauthenticated data extraction possible through store-api.order endpoint | HIGH | 8.9 | Mar 11, 2026 |
| CVE-2023-22733 | Improper Output Neutralization in Log Module in shopware | MEDIUM | 6.5 | Jan 17, 2023 |
| CVE-2023-22732 | Insufficient Session Expiration in Administration in shopware | CRITICAL | 9.8 | Jan 17, 2023 |
| CVE-2023-22731 | Improper Control of Generation of Code in Twig rendered views in shopware | CRITICAL | 10.0 | Jan 17, 2023 |
| CVE-2023-22730 | Improper Input Validation of Clearance sale in cart | HIGH | 7.5 | Jan 17, 2023 |
| CVE-2023-22734 | Improper Input Newsletter subscription option validation in shopware | HIGH | 7.5 | Jan 17, 2023 |
| CVE-2022-24872 | Improper Access Control in shopware | HIGH | 8.1 | Apr 20, 2022 |
| CVE-2022-24871 | Server-Side Request Forgery (SSRF) in Shopware | HIGH | 7.2 | Apr 20, 2022 |
| CVE-2022-24744 | Insufficient Session Expiration in shopware | LOW | 3.5 | Mar 9, 2022 |
| CVE-2022-24745 | Guest session is shared between customers in shopware | MEDIUM | 6.5 | Mar 9, 2022 |
| CVE-2022-24746 | HTML injection possibility in voucher code form | MEDIUM | 6.1 | Mar 9, 2022 |
| CVE-2022-24747 | HTTP caching is marking private HTTP headers as public | MEDIUM | 6.3 | Mar 9, 2022 |
| CVE-2022-24748 | Incorrect Authentication in shopware | HIGH | 7.5 | Mar 9, 2022 |
| CVE-2021-37711 | Authenticated server-side request forgery in file upload via URL. | HIGH | 8.8 | Aug 16, 2021 |
| CVE-2021-37710 | Cross-Site Scripting via SVG media files | HIGH | 8.0 | Aug 16, 2021 |
Showing 1 to 25 of 33 CVEs