Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
shopware vulnerabilities and exploits
(subscribe to this query)
445
VMScore
CVE-2021-32711
Shopware is an open source eCommerce platform. Versions before 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected by t...
Shopware Shopware
445
VMScore
CVE-2020-13997
In Shopware prior to 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.
Shopware Shopware
435
VMScore
CVE-2017-15374
Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remote attackers are able to inject malicious script code into the firstname, lastname, or order input fields to provoke persistent exe...
Shopware Shopware 5.2.5
Shopware Shopware 5.3.0
Shopware Shopware 5.2.27
Shopware Shopware 5.2.26
Shopware Shopware 5.2.25
Shopware Shopware 5.2.24
Shopware Shopware 5.2.23
Shopware Shopware 5.2.22
Shopware Shopware 5.2.21
Shopware Shopware 5.2.20
Shopware Shopware 5.2.19
Shopware Shopware 5.2.18
Shopware Shopware 5.2.17
Shopware Shopware 5.2.16
Shopware Shopware 5.2.15
Shopware Shopware 5.2.14
Shopware Shopware 5.2.13
Shopware Shopware 5.2.12
Shopware Shopware 5.2.11
Shopware Shopware 5.2.10
Shopware Shopware 5.2.9
Shopware Shopware 5.2.8
1 EDB exploit
405
VMScore
CVE-2017-18357
Shopware prior to 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.
Shopware Shopware
1 EDB exploit
383
VMScore
CVE-2022-24873
Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopw...
Shopware Shopware
383
VMScore
CVE-2022-24746
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions it is possible to inject code via the voucher code form. This issue has been patched in version 6.4.8.1. There are no known workarounds for this issue.
Shopware Shopware
383
VMScore
CVE-2019-12935
Shopware prior to 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
Shopware Shopware
356
VMScore
CVE-2022-24956
An issue exists in Shopware B2B-Suite up to and including 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability ...
Shopware B2b Suite
356
VMScore
CVE-2021-37709
Shopware is an open source eCommerce platform. Versions before 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corres...
Shopware Shopware
356
VMScore
CVE-2021-32716
Shopware is an open source eCommerce platform. In versions before 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.1. You can get the update to 6.4.1.1 regula...
Shopware Shopware
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-38627
CVE-2022-45803
CVE-2024-38319
camera
template injection
CVE-2024-27801
CVE-2024-0762
CVE-2024-5791
unauthorized
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »