CVEs we hold for Shopware
Records whose assigning authority named Shopware as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-48016Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-paymentshopware; shopware platform CVE-2026-48015Shopware: Stored XSS via SVG file upload — no SVG sanitizationshopware; shopware platform CVE-2026-48014Shopware: Admin API ACL Bypass in Order State Transition Endpointsshopware; shopware platform CVE-2026-48013Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validationshopware; shopware platform CVE-2026-48012Shopware SSO referer trust leading to an arbitrary redirect targetshopware; shopware platform CVE-2026-48011Shopware: Timing-attack on admin panel allowing enumeration of administrator usernamesshopware CVE-2026-48010Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accountsshopware; shopware platform CVE-2026-48009Shopware: Admin Account Takeover via User Recovery Hash Exposureshopware; shopware platform CVE-2026-48008Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypassshopware; shopware platform CVE-2026-32142shopware/commercial: `/api/_info/config` route exposes information about licensesshopware commercial CVE-2026-31889Shopware has a potential take over of app credentialsshopware platform CVE-2026-31888Shopware has user enumeration via distinct error codes on Store API login endpointshopware platform CVE-2026-31887Shopware unauthenticated data extraction possible through store-api.order endpointshopware platform CVE-2026-23498Shopware Improper Control of Generation of Code in Twig rendered viewsshopware CVE-2025-7954Race Condition in Shopware Voucher SubmissionShopware CVE-2025-67648Shopware's inproper input validation can lead to Reflected XSS through Storefront Login Pageshopware CVE-2025-32378Shopware's default newsletter opt-in settings allow for mass sign-up abuseshopware CVE-2025-30151Shopware allows Denial Of Service via password lengthshopware CVE-2025-30150Shopware 6 allows attackers to check for registered accounts through the store-apishopware CVE-2024-42357Shopware vulnerable to blind SQL-injection in DAL aggregationsshopware CVE-2024-42356Shopware vulnerable to Server Side Template Injection in Twig using Context functionsshopware CVE-2024-42355Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagshopware CVE-2024-42354Shopware vulnerable to Improper Access Control with ManyToMany associations in store-apishopware CVE-2024-31447Shopware has Improper Session Handling in store-apishopware CVE-2024-27917Shopware's session is persistent in Cache for 404 pagesshopware CVE-2024-22408Server-Side Request Forgery (SSRF) in Shopware Flow Buildershopware CVE-2024-22406Blind SQL-injection in DAL aggregations in Shopwareshopware CVE-2023-23941SwagPayPal payment not sent to PayPal correctlyshopware SwagPayPal CVE-2023-22734Improper Input Newsletter subscription option validation in shopwareshopware platform CVE-2023-22733Improper Output Neutralization in Log Module in shopwareshopware platform CVE-2023-22732Insufficient Session Expiration in Administration in shopwareshopware platform CVE-2023-22731Improper Control of Generation of Code in Twig rendered views in shopwareshopware platform CVE-2023-22730Improper Input Validation of Clearance sale in cartshopware platform CVE-2023-2017Improper Control of Generation of Code in Twig Rendered Views in ShopwareShopware 6 CVE-2022-36102Acess control list bypassed via crafted specific URLsshopware CVE-2022-31148Persistent cross site scripting in customer module in Shopwareshopware CVE-2022-31057Authenticated Stored XSS in Shopware Administrationshopware CVE-2022-24892Multiple valid tokens for password reset in Shopwareshopware CVE-2022-24879Malfunction of Cross-Site Request Forgery token validationshopware CVE-2022-24873Non-Stored Cross-site Scripting in Shopware storefrontshopware CVE-2022-24871Server-Side Request Forgery (SSRF) in Shopwareshopware platform CVE-2022-24747HTTP caching is marking private HTTP headers as publicshopware platform CVE-2022-24746HTML injection possibility in voucher code formshopware platform CVE-2022-24745Guest session is shared between customers in shopwareshopware platform CVE-2022-24744Insufficient Session Expiration in shopwareshopware platform CVE-2021-37711Authenticated server-side request forgery in file upload via URL.shopware platform CVE-2021-37710Cross-Site Scripting via SVG media filesshopware platform CVE-2021-37709Insecure direct object reference of log files of the Import/Export featureshopware platform CVE-2021-37708Command injection in mail agent settingsshopware platform CVE-2021-37707Manipulation of product reviews via APIshopware platform CVE-2021-32717Private files publicly accessible with Cloud Storage providersshopware platform CVE-2021-32716Internal hidden fields are visible on to many associations in admin apishopware platform CVE-2021-32710Potential Session Hijacking in Shopwareshopware platform CVE-2021-32709Creation of order credits was not validated by acl in admin ordersshopware platform 66 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.