<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Shopware (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/shopware.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/shopware-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Shopware (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:59 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-31889 – Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31889</guid>
    <pubDate>Wed, 11 Mar 2026 20:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31889</strong></p>
  <p>Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow used HMAC‑based authentication without sufficiently binding a shop installation to its original domain. During re‑regist…</p>
  <p><strong>CVSS:</strong> 8.9 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31887 – Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insuff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31887</guid>
    <pubDate>Wed, 11 Mar 2026 19:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31887</strong></p>
  <p>Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability is fixed in 6.7.8.1 and 6.6.10.15.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23498 – Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23498</guid>
    <pubDate>Wed, 14 Jan 2026 19:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23498</strong></p>
  <p>Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure not checked being against allow list for the map(...) override. This vulnerability is fixed in 6.7.6.1.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67648 – Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67648</guid>
    <pubDate>Thu, 11 Dec 2025 00:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67648</strong></p>
  <p>Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template of the Storefront login page without further processing or input validation. This allows direct code injection into the template via the URL parameter…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7954 – A race condition vulnerability has been identified in Shopware's voucher system ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7954</guid>
    <pubDate>Wed, 06 Aug 2025 08:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7954</strong></p>
  <p>A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30151 – Shopware is an open commerce platform. It's possible to pass long passwords that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30151</guid>
    <pubDate>Tue, 08 Apr 2025 14:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30151</strong></p>
  <p>Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42357 – Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42357</guid>
    <pubDate>Thu, 08 Aug 2024 15:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42357</strong></p>
  <p>Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in the `aggregations` object. The `name` field in this `aggregations` object is vulnerable…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42356 – Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42356</guid>
    <pubDate>Thu, 08 Aug 2024 15:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42356</strong></p>
  <p>Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to access to current language, currency information. The context object allows also to switch for a short time the scope of the Context as a helper with a callable function. The function can be called also from Twig and as the second parameter…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42355 – Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42355</guid>
    <pubDate>Thu, 08 Aug 2024 15:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42355</strong></p>
  <p>Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag name to silence, but this parameter is not escaped properly and allows execution of code. Update to Shopware 6.6.5.1 or 6.5.8.13 to receive a patch. For older ver…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27917 – Shopware is an open commerce platform based on Symfony Framework and Vue. The Sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27917</guid>
    <pubDate>Wed, 06 Mar 2024 20:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27917</strong></p>
  <p>Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the Response. Since Shopware 6.5.8.0, the 404 pages are cached to improve the performance of 404 pages. So the cached Response which contains a Session Cookie when the Browser accessing the 404 page, has no cookies yet. The Symfony Session Handler is in u…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-524</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22408 – Shopware is an open headless commerce platform. The implemented Flow Builder fun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22408</guid>
    <pubDate>Tue, 16 Jan 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22408</strong></p>
  <p>Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate the URL used when creating the “call webhook” action. This enables malicious users to perform web requests to internal hosts. This issue has been fixed in the Commercial Plugin release 6.5.7.4 or with the Security Plugin. For installations with Shopwa…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22406 – Shopware is an open headless commerce platform. The Shopware application API con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22406</guid>
    <pubDate>Tue, 16 Jan 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22406</strong></p>
  <p>Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in the “aggregations” object. The ‘name’ field in this “aggregations” object is vulnerable SQL-injection and can be exploi…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2017 – Server-side Template Injection (SSTI) in Shopware 6 (&lt;= v6.4.20.0, v6.5.0.0-rc1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2017</guid>
    <pubDate>Mon, 17 Apr 2023 11:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2017</strong></p>
  <p>Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the validation checks in `Shopware\Core\Framework\Adapter\Twig\SecurityExtension` and call any arbitrary PHP function and thus exec…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-23941 – SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based Pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23941</guid>
    <pubDate>Fri, 03 Feb 2023 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-23941</strong></p>
  <p>SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, Credit card), the amount and item list sent to PayPal may not be identical to the one in the created order. The problem has been fixed with version 5.4.4. As a workaround, disable the aforementioned payment methods or use the S…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-22731 – Shopware is an open source commerce platform based on Symfony Framework and Vue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22731</guid>
    <pubDate>Tue, 17 Jan 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-22731</strong></p>
  <p>Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows a template to call any global PHP function and thus execute arbitrary code. The attacker must have access to a Twig environment in order to exploit this vulner…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24879 – Shopware is an open source e-commerce software platform. Versions prior to 5.7.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24879</guid>
    <pubDate>Thu, 28 Apr 2022 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24879</strong></p>
  <p>Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24872 – Shopware is an open commerce platform based on Symfony Framework and Vue. Permis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24872</guid>
    <pubDate>Wed, 20 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24872</strong></p>
  <p>Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable within normal user session. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. There are no known workarounds for this issue.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24871 – Shopware is an open commerce platform based on Symfony Framework and Vue. In aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24871</guid>
    <pubDate>Wed, 20 Apr 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24871</strong></p>
  <p>Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update internal resources. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. There are no known workarounds for…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37710 – Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37710</guid>
    <pubDate>Mon, 16 Aug 2021 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37710</strong></p>
  <p>Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37708 – Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37708</guid>
    <pubDate>Mon, 16 Aug 2021 20:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37708</strong></p>
  <p>Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32717 – Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 priv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32717</guid>
    <pubDate>Thu, 24 Jun 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32717</strong></p>
  <p>Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the documentation. The visibility must be at the same level as `type`. When the Storage is saved on Amazon AWS we recommending disa…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-32711 – Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may lea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32711</guid>
    <pubDate>Thu, 24 Jun 2021 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-32711</strong></p>
  <p>Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected by this change. We recommend to update to the current version 6.3.5.1. You can get the update to 6.3.5.1 regularly via th…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-28199 – best it Amazon Pay Plugin before 9.4.2 for Shopware exposes Sensitive Informatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28199</guid>
    <pubDate>Fri, 26 Feb 2021 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-28199</strong></p>
  <p>best it Amazon Pay Plugin before 9.4.2 for Shopware exposes Sensitive Information to an Unauthorized Actor.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13997 – In Shopware before 6.2.3, the database password is leaked to an unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13997</guid>
    <pubDate>Tue, 28 Jul 2020 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13997</strong></p>
  <p>In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13970 – Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13970</guid>
    <pubDate>Tue, 28 Jul 2020 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13970</strong></p>
  <p>Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12935 – Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12935</guid>
    <pubDate>Sun, 23 Jun 2019 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12935</strong></p>
  <p>Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12799 – In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web req...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12799</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12799</guid>
    <pubDate>Thu, 13 Jun 2019 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12799</strong></p>
  <p>In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12799">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-20713 – Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-20713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-20713</guid>
    <pubDate>Tue, 15 Jan 2019 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-20713</strong></p>
  <p>Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-3109 – The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3109</guid>
    <pubDate>Fri, 21 Apr 2017 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-3109</strong></p>
  <p>The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3109">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
