Shopware
Shopware: vulnerabilidades y CVE
Shopware tiene 78 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE78
Últimos 12 meses16
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-48013 | Media (4.1) | 0.37% | — | 23 jul 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP… |
| CVE-2026-48012 | Media (4.3) | 0.27% | — | 23 jul 2026 | Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is reached without the expected SSO… |
| CVE-2026-48016 | Media (4.3) | 0.41% | — | 17 jul 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment in src/Core/Checkout/Payment/SalesChannel/HandlePaymentMethodRoute.php accepts a user-controlled… |
| CVE-2026-48015 | Media (4.9) | 0.48% | — | 17 jul 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via the media… |
| CVE-2026-48014 | Media (6.5) | 0.39% | — | 17 jul 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{transition} and similar transaction and delivery transition routes in… |
| CVE-2026-48010 | Media (6.5) | 0.47% | — | 17 jul 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the… |
| CVE-2026-48009 | Media (6.8) | 0.46% | — | 17 jul 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering POST /api/_action/user/user-recovery, reading… |
| CVE-2026-48008 | Media (6.5) | 0.47% | — | 17 jul 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through… |
| CVE-2026-48011 | Baja (3.7) | 0.36% | — | 10 jun 2026 | Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix… |
| CVE-2026-32142 | Media (5.3) | 0.33% | — | 12 mar 2026 | Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is fixed in 7.8.1 and 6.10.15. |
| CVE-2026-32100 | Media (5.3) | 0.33% | — | 12 mar 2026 | Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vulnerability is fixed in 2.0.16, 3.0.12, and 4.0.7. |
| CVE-2026-31889 | Alta (8.9) | 0.41% | — | 11 mar 2026 | Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel… |
| CVE-2026-31888 | Media (5.3) | 0.34% | — | 11 mar 2026 | Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different error codes depending on whether the submitted email address belongs… |
| CVE-2026-31887 | Alta (8.9) | 0.39% | — | 11 mar 2026 | Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode… |
| CVE-2026-23498 | Alta (7.2) | 0.45% | — | 14 ene 2026 | Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure not checked being against allow list for the map(...) override. This… |
| CVE-2025-67648 | Media (6.1) | 0.19% | — | 11 dic 2025 | Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly… |
| CVE-2025-7954 | Media (6) | 0.39% | — | 6 ago 2025 | A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations. |
| CVE-2025-51541 | Media (6.1) | 0.38% | — | 5 ago 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c_database_schema field fails to properly sanitize user-supplied input… |
| CVE-2025-27892 | Media (6.8) | 13% | — | 15 abr 2025 | Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression. |
| CVE-2025-32378 | Media (6.9) | 0.30% | — | 9 abr 2025 | Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolicited newsletter sign-ups without confirmation. Default settings are… |
| CVE-2025-30151 | Alta (7.5) | 0.41% | — | 8 abr 2025 | Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older… |
| CVE-2025-30150 | Media (5.5) | 0.39% | — | 8 abr 2025 | Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api… |
| CVE-2024-42357 | Crítica (9.8) | 0.60% | — | 8 ago 2024 | Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search through information stored within their Shopware… |
| CVE-2024-42356 | Alta (7.2) | 0.65% | — | 8 ago 2024 | Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to access to current language, currency information. The context… |
| CVE-2024-42355 | Crítica (9.8) | 0.86% | — | 8 ago 2024 | Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string… |
| CVE-2024-42354 | Media (5.9) | 0.43% | — | 8 ago 2024 | Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be marked as ApiAware in the EntityDefinition. So only ApiAware fields of the… |
| CVE-2024-31447 | Media (5.3) | 0.50% | — | 8 abr 2024 | Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when a authenticated request is made to `POST… |
| CVE-2024-27917 | Alta (7.5) | 0.61% | — | 6 mar 2024 | Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the Response. Since Shopware 6.5.8.0, the 404 pages are cached to improve… |
| CVE-2024-22408 | Alta (8.1) | 0.37% | — | 16 ene 2024 | Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate the URL used when creating the “call webhook” action. This enables… |
| CVE-2024-22407 | Media (6.5) | 0.40% | — | 16 ene 2024 | Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that modify the payment, delivery, and/or order status. Due… |