vciy

CVEs we hold for Shopware

Records whose assigning authority named Shopware as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-48016Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-paymentshopware; shopware platform
CVE-2026-48015Shopware: Stored XSS via SVG file upload — no SVG sanitizationshopware; shopware platform
CVE-2026-48014Shopware: Admin API ACL Bypass in Order State Transition Endpointsshopware; shopware platform
CVE-2026-48013Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validationshopware; shopware platform
CVE-2026-48012Shopware SSO referer trust leading to an arbitrary redirect targetshopware; shopware platform
CVE-2026-48011Shopware: Timing-attack on admin panel allowing enumeration of administrator usernamesshopware
CVE-2026-48010Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accountsshopware; shopware platform
CVE-2026-48009Shopware: Admin Account Takeover via User Recovery Hash Exposureshopware; shopware platform
CVE-2026-48008Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypassshopware; shopware platform
CVE-2026-32142shopware/commercial: `/api/_info/config` route exposes information about licensesshopware commercial
CVE-2026-31889Shopware has a potential take over of app credentialsshopware platform
CVE-2026-31888Shopware has user enumeration via distinct error codes on Store API login endpointshopware platform
CVE-2026-31887Shopware unauthenticated data extraction possible through store-api.order endpointshopware platform
CVE-2026-23498Shopware Improper Control of Generation of Code in Twig rendered viewsshopware
CVE-2025-7954Race Condition in Shopware Voucher SubmissionShopware
CVE-2025-67648Shopware's inproper input validation can lead to Reflected XSS through Storefront Login Pageshopware
CVE-2025-32378Shopware's default newsletter opt-in settings allow for mass sign-up abuseshopware
CVE-2025-30151Shopware allows Denial Of Service via password lengthshopware
CVE-2025-30150Shopware 6 allows attackers to check for registered accounts through the store-apishopware
CVE-2024-42357Shopware vulnerable to blind SQL-injection in DAL aggregationsshopware
CVE-2024-42356Shopware vulnerable to Server Side Template Injection in Twig using Context functionsshopware
CVE-2024-42355Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagshopware
CVE-2024-42354Shopware vulnerable to Improper Access Control with ManyToMany associations in store-apishopware
CVE-2024-31447Shopware has Improper Session Handling in store-apishopware
CVE-2024-27917Shopware's session is persistent in Cache for 404 pagesshopware
CVE-2024-22408Server-Side Request Forgery (SSRF) in Shopware Flow Buildershopware
CVE-2024-22407Broken Access Control order API in Shopwareshopware
CVE-2024-22406Blind SQL-injection in DAL aggregations in Shopwareshopware
CVE-2023-34099Improper mail validation in Shopwareshopware
CVE-2023-34098Dependency configuration exposed in Shopwareshopware
CVE-2023-23941SwagPayPal payment not sent to PayPal correctlyshopware SwagPayPal
CVE-2023-22734Improper Input Newsletter subscription option validation in shopwareshopware platform
CVE-2023-22733Improper Output Neutralization in Log Module in shopwareshopware platform
CVE-2023-22732Insufficient Session Expiration in Administration in shopwareshopware platform
CVE-2023-22731Improper Control of Generation of Code in Twig rendered views in shopwareshopware platform
CVE-2023-22730Improper Input Validation of Clearance sale in cartshopware platform
CVE-2023-2017Improper Control of Generation of Code in Twig Rendered Views in ShopwareShopware 6
CVE-2022-36102Acess control list bypassed via crafted specific URLsshopware
CVE-2022-36101Sensitive data in backend customer moduleshopware
CVE-2022-31148Persistent cross site scripting in customer module in Shopwareshopware
CVE-2022-31057Authenticated Stored XSS in Shopware Administrationshopware
CVE-2022-24892Multiple valid tokens for password reset in Shopwareshopware
CVE-2022-24879Malfunction of Cross-Site Request Forgery token validationshopware
CVE-2022-24873Non-Stored Cross-site Scripting in Shopware storefrontshopware
CVE-2022-24872Improper Access Control in shopwareshopware platform
CVE-2022-24871Server-Side Request Forgery (SSRF) in Shopwareshopware platform
CVE-2022-24748Incorrect Authentication in shopwareshopware platform
CVE-2022-24747HTTP caching is marking private HTTP headers as publicshopware platform
CVE-2022-24746HTML injection possibility in voucher code formshopware platform
CVE-2022-24745Guest session is shared between customers in shopwareshopware platform
CVE-2022-24744Insufficient Session Expiration in shopwareshopware platform
CVE-2022-21652Insufficient Session Expiration in shopwareshopware
CVE-2022-21651Open redirect in shopwareshopware
CVE-2021-41188Authenticated Stored XSS in Administrationshopware
CVE-2021-37711Authenticated server-side request forgery in file upload via URL.shopware platform
CVE-2021-37710Cross-Site Scripting via SVG media filesshopware platform
CVE-2021-37709Insecure direct object reference of log files of the Import/Export featureshopware platform
CVE-2021-37708Command injection in mail agent settingsshopware platform
CVE-2021-37707Manipulation of product reviews via APIshopware platform
CVE-2021-32717Private files publicly accessible with Cloud Storage providersshopware platform
CVE-2021-32716Internal hidden fields are visible on to many associations in admin apishopware platform
CVE-2021-32713Authenticated Stored XSSshopware
CVE-2021-32712Information leakage in Error Handlershopware
CVE-2021-32711Leak of information via Store-APIshopware platform
CVE-2021-32710Potential Session Hijacking in Shopwareshopware platform
CVE-2021-32709Creation of order credits was not validated by acl in admin ordersshopware platform

66 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.