shopware/platform
Packagist50 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting shopware/platformpage 1 of 1
- CVE-2020-13970HIGHCVSS 8.8EG 8.8fixed in 6.2.32020-07-28
vulnerable: v6.0.0+ea2 ... v6.2.2 (16 versions)
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform serve…
- CVE-2020-13971MEDIUMCVSS 5.4EG 5.4fixed in 6.2.32020-07-28
vulnerable: v6.0.0+ea2 ... v6.2.2 (16 versions)
In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.
- CVE-2020-13997HIGHCVSS 7.5EG 7.5fixed in 6.2.32020-07-28
vulnerable: v6.1.0 ... v6.2.2 (15 versions)
In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.
- CVE-2021-32709MEDIUMCVSS 4.9EG 4.9fixed in 6.4.1.12021-06-24
vulnerable: 6.3.0.0 ... v6.2.3 (36 versions)
Shopware is an open source eCommerce platform. Creation of order credits was not validated by ACL in admin orders. Users are recommend to update to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updat…
- CVE-2021-32710MEDIUMCVSS 5.9EG 5.9fixed in 6.3.5.22021-06-24
vulnerable: 6.3.0.0 ... v6.2.3 (30 versions)
Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2. We recommend to update to the current version 6.3.5.2. You can get the update to 6.3.5.2 regularly via the Auto-Update…
- CVE-2021-32711CRITICALCVSS 9.1EG 9.1fixed in 6.3.5.12021-06-24
vulnerable: 6.3.0.0 ... v6.2.3 (29 versions)
Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consume…
- CVE-2021-32716MEDIUMCVSS 4.4EG 4.4fixed in 6.4.1.12021-06-24
vulnerable: 6.3.0.0 ... v6.2.3 (36 versions)
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.…
- CVE-2021-32717HIGHCVSS 7.5EG 7.5fixed in 6.4.1.12021-06-24
vulnerable: 6.3.0.0 ... v6.2.3 (36 versions)
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the cor…
- CVE-2021-37707MEDIUMCVSS 6.5EG 6.5fixed in 6.4.3.12021-08-16
vulnerable: 6.3.0.0 ... v6.2.3 (41 versions)
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability that allows manipulation of product reviews via API. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3,…
- CVE-2021-37708HIGHCVSS 8.8EG 8.8fixed in 6.4.3.12021-08-16
vulnerable: 6.3.0.0 ... v6.2.3 (41 versions)
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, correspond…
- CVE-2021-37709MEDIUMCVSS 6.5EG 6.5fixed in 6.4.3.12021-08-16
vulnerable: 6.3.0.0 ... v6.2.3 (41 versions)
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch. As workarounds for …
- CVE-2021-37710HIGHCVSS 8.0EG 8.0fixed in 6.4.3.12021-08-16
vulnerable: 6.3.0.0 ... v6.2.3 (41 versions)
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, correspond…
- CVE-2021-37711HIGHCVSS 8.8EG 8.8fixed in 6.4.3.12021-08-16
vulnerable: 6.3.0.0 ... v6.2.3 (41 versions)
Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures …
- CVE-2022-24744LOWCVSS 2.6EG 2.6fixed in 6.4.8.12022-03-09
vulnerable: 6.3.0.0 ... v6.2.3 (50 versions)
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue has been resolved i…
- CVE-2022-24745MEDIUMCVSS 4.8EG 4.8fixed in 6.4.8.22022-03-09
vulnerable: 6.3.0.0 ... v6.2.3 (51 versions)
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inconsistent experienc…
- CVE-2022-24746MEDIUMCVSS 6.1EG 6.1fixed in 6.4.8.12022-03-09
vulnerable: 6.3.0.0 ... v6.2.3 (50 versions)
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions it is possible to inject code via the voucher code form. This issue has been patched in version 6.4.8.1. There …
- CVE-2022-24747MEDIUMCVSS 6.3EG 6.3fixed in 6.4.8.22022-03-09
vulnerable: 6.3.0.0 ... v6.2.3 (51 versions)
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no properly set sensitive HTTP headers to be non-cacheable. If there is an HTTP cache between the s…
- CVE-2022-24871HIGHCVSS 7.2EG 7.2fixed in 6.4.10.12022-04-20
vulnerable: 6.3.0.0 ... v6.2.3 (54 versions)
Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update internal resources. Users are advised to update to the current…
- CVE-2022-24872HIGHCVSS 8.1EG 8.1fixed in 6.4.10.12022-04-20
vulnerable: 6.3.0.0 ... v6.2.3 (54 versions)
Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable within normal user session. Users are advised to update to the current version 6.4.10.1. For o…
- CVE-2023-2017HIGHCVSS 8.8EG 8.8fixed in 6.4.20.12023-04-17
vulnerable: 6.3.0.0 ... v6.2.3 (72 versions)
Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the…
- CVE-2023-22730MEDIUMCVSS 5.3EG 5.3fixed in 6.4.18.12023-01-17
vulnerable: 6.3.0.0 ... v6.2.3 (69 versions)
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item multiple times in the cart using the AP. The Cart Validators checked the line item's individ…
- CVE-2023-22731CRITICALCVSS 9.9EG 9.9fixed in 6.4.18.12023-01-17
vulnerable: 6.3.0.0 ... v6.2.3 (69 versions)
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows…
- CVE-2023-22732LOWCVSS 3.7EG 3.7fixed in 6.4.18.12023-01-17
vulnerable: 6.3.0.0 ... v6.2.3 (69 versions)
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time. In v…
- CVE-2023-22733LOWCVSS 2.7EG 2.7fixed in 6.4.18.12023-01-17
vulnerable: 6.3.0.0 ... v6.2.3 (69 versions)
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of sent mails. An attacker with access to either the local system logs or a centralized loggin…
- CVE-2023-22734MEDIUMCVSS 4.3EG 4.3fixed in 6.4.18.12023-01-17
vulnerable: 6.3.0.0 ... v6.2.3 (69 versions)
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly, and it was possible to skip the complete double opt in process. As a result operators may…
- CVE-2024-22406CRITICALCVSS 9.3EG 9.3fixed in 6.5.7.42024-01-16
vulnerable: 6.3.0.0 ... v6.5.7.3 (98 versions)
Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function c…
- CVE-2024-22407MEDIUMCVSS 4.9EG 4.9fixed in 6.5.7.42024-01-16
vulnerable: 6.3.0.0 ... v6.5.7.3 (98 versions)
Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that modify the payment, delivery, and/or order status. Due to this inadequate i…
- CVE-2024-27917HIGHCVSS 7.5EG 7.5fixed in 6.5.8.72024-03-06
vulnerable: v6.5.8.0 ... v6.5.8.6 (7 versions)
Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the Response. Since Shopware 6.5.8.0, the 404 pages are cached to improve the performance of 40…
- CVE-2024-31447MEDIUMCVSS 5.3EG 5.3fixed in 6.5.8.8 or 6.6.1.0, by version range2024-04-08
vulnerable: v6.6.0.0 ... v6.6.0.3 (11 versions)
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when a authenticated request is made to `POST /store-api/account/logout`, the cart will be c…
- CVE-2024-42354MEDIUMCVSS 5.3EG 5.3fixed in 6.5.8.13 or 6.6.5.1, by version range2024-08-08
vulnerable: v6.6.0.0 ... v6.6.5.0 (13 versions)
Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be marked as ApiAware in the EntityDefinition. So only ApiAware fields of the EntityDefinition wi…
- CVE-2024-42355HIGHCVSS 8.3EG 8.3fixed in 6.5.8.13 or 6.6.5.1, by version range2024-08-08
vulnerable: v6.6.0.0 ... v6.6.5.0 (13 versions)
Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag na…
- CVE-2024-42356HIGHCVSS 8.3EG 8.3fixed in 6.5.8.13 or 6.6.5.1, by version range2024-08-08
vulnerable: v6.6.0.0 ... v6.6.5.0 (13 versions)
Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to access to current language, currency information. The context object allows also …
- CVE-2024-42357HIGHCVSS 7.3EG 7.3fixed in 6.5.8.13 or 6.6.5.1, by version range2024-08-08
vulnerable: v6.6.0.0 ... v6.6.5.0 (13 versions)
Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The search…
- CVE-2025-27892MEDIUMCVSS 6.8EG 6.8fixed in 6.7.0.0-rc2, 6.6.10.3 or 6.5.8.18, by version range2025-04-15
vulnerable: 6.3.0.0 ... v6.5.8.9 (117 versions)
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.
- CVE-2025-30150MEDIUMCVSS 5.3EG 5.3fixed in 6.6.10.3, 6.7.0.0-rc2 or 6.5.8.18, by version range2025-04-08
vulnerable: 6.3.0.0 ... v6.5.8.9 (117 versions)
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api endpoint /store-api/accoun…
- CVE-2025-30151HIGHCVSS 7.5EG 7.5fixed in 6.6.10.3, 6.7.0.0-rc2 or 6.5.8.17, by version range2025-04-08
vulnerable: 6.3.0.0 ... v6.5.8.9 (116 versions)
Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresp…
- CVE-2025-32378MEDIUMCVSS 5.3EG 5.3fixed in 6.6.10.3, 6.7.0.0-rc2 or 6.5.8.17, by version range2025-04-09
vulnerable: 6.3.0.0 ... v6.5.8.9 (116 versions)
Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolicited newsletter sign-ups without confirmation. Default settings are Newsletter: Double Opt…
- CVE-2025-7954HIGHCVSS 8.1EG 8.12025-08-06
vulnerable: 6.3.0.0 ... v6.6.9.0 (153 versions)
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
- CVE-2026-31887HIGHCVSS 7.5EG 7.5fixed in 6.7.8.1 or 6.6.10.15, by version range2026-03-11
vulnerable: 6.3.0.0 ... v6.6.9.0 (163 versions)
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the stor…
- CVE-2026-31888MEDIUMCVSS 5.3EG 5.3fixed in 6.7.8.1 or 6.6.10.14, by version range2026-03-11
vulnerable: 6.3.0.0 ... v6.6.9.0 (162 versions)
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different error codes depending on whether the submitted email address belongs to a registered cust…
- CVE-2026-31889HIGHCVSS 8.9EG 8.9fixed in 6.7.8.1 or 6.6.10.15, by version range2026-03-11
vulnerable: 6.3.0.0 ... v6.6.9.0 (163 versions)
Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and a…
- CVE-2026-48008MEDIUMCVSS 6.5EG 6.5fixed in 6.7.10.1 or 6.6.10.18, by version range2026-06-04
vulnerable: 6.3.0.0 ... v6.6.9.0 (166 versions)
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API POST /ap…
- CVE-2026-48009MEDIUMCVSS 6.8EG 6.8fixed in 6.7.10.1 or 6.6.10.18, by version range2026-06-04
vulnerable: 6.3.0.0 ... v6.6.9.0 (166 versions)
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering POST /api/_action/user/user-recovery, reading the password recover…
- CVE-2026-48010MEDIUMCVSS 6.5EG 6.5fixed in 6.7.10.1 or 6.6.10.18, by version range2026-06-04
vulnerable: 6.3.0.0 ... v6.6.9.0 (166 versions)
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the admin field, so a non-a…
- CVE-2026-48011LOWCVSS 3.7EG 3.7fixed in 6.7.10.1 or 6.6.10.18, by version range2026-06-04
vulnerable: 6.3.0.0 ... v6.6.9.0 (166 versions)
Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.
- CVE-2026-48012MEDIUMCVSS 4.3EG 4.3fixed in 6.7.10.12026-06-04
vulnerable: v6.7.10.0 ... v6.7.9.1 (18 versions)
Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is reached without the expected SSO session state, the appl…
- CVE-2026-48013MEDIUMCVSS 4.1EG 4.1fixed in 6.7.10.12026-06-04
vulnerable: v6.7.0.0 ... v6.7.9.1 (26 versions)
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP addresses. While the p…
- CVE-2026-48014MEDIUMCVSS 6.5EG 6.5fixed in 6.7.10.1 or 6.6.10.18, by version range2026-06-04
vulnerable: 6.3.0.0 ... v6.6.9.0 (166 versions)
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{transition} and similar transaction and delivery transition routes in src/Core/Checkout/Order/A…
- CVE-2026-48015MEDIUMCVSS 4.9EG 4.9fixed in 6.7.10.1 or 6.6.10.18, by version range2026-06-04
vulnerable: 6.3.0.0 ... v6.6.9.0 (166 versions)
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via the media manager without SVG c…
- CVE-2026-48016MEDIUMCVSS 4.3EG 4.3fixed in 6.7.10.1 or 6.6.10.18, by version range2026-06-04
vulnerable: 6.3.0.0 ... v6.6.9.0 (166 versions)
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment in src/Core/Checkout/Payment/SalesChannel/HandlePaymentMethodRoute.php accepts a user-controlled orderId and forwards …
Check whether shopware/platform is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for shopware/platform CVEs against the assets you own.
Book a Demo →