shopware/platform
The Shopware e-commerce core
Security Advisories for shopware/platform in packagist
Moderate
3 months ago
Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation
packagist
shopware/platform, shopware/core
Moderate
3 months ago
Shopware: Stored XSS via SVG file upload โ no SVG sanitization
packagist
shopware/platform, shopware/core
Moderate
3 months ago
Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment
packagist
shopware/core, shopware/platform
Moderate
3 months ago
Shopware: Admin API ACL Bypass in Order State Transition Endpoints
packagist
shopware/core, shopware/platform
Moderate
3 months ago
Shopware SSO referer trust leading to an arbitrary redirect target
packagist
shopware/platform, shopware/core
Low
3 months ago
Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames
packagist
shopware/core, shopware/platform
Moderate
3 months ago
Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts
packagist
shopware/core, shopware/platform
Moderate
3 months ago
Shopware: Admin Account Takeover via User Recovery Hash Exposure
packagist
shopware/core, shopware/platform
Moderate
3 months ago
Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass
packagist
shopware/core, shopware/platform
High
6 months ago
Shopware vulnerable to a potential take over of app credentials
packagist
shopware/core, shopware/platform
Moderate
6 months ago
Shopware has user enumeration via distinct error codes on Store API login endpoint
packagist
shopware/core, shopware/platform
High
6 months ago
Shopware: Unauthenticated data extraction possible through store-api.order endpoint
packagist
shopware/platform, shopware/core
Moderate
11 months ago
Shopware Customer Orders can be canceled, even if refunds are disabled
packagist
shopware/core, shopware/platform
Moderate
11 months ago
Shopware exposes sensitive user information via CSV export mapping
packagist
shopware/core, shopware/platform
Low
11 months ago
Shopware vulnerable to Server-Side Request Forgery (SSRF) โ order invoice
packagist
shopware/core, shopware/platform
Low
11 months ago
Shopware vulnerable to path traversal via Plugin upload
packagist
shopware/core, shopware/platform
Moderate
11 months ago
Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually
packagist
shopware/core, shopware/platform
Potential
High
12 months ago
Shopware: Reflective Cross Site-Scripting (XSS) in CMS components
packagist
shopware/core, shopware/shopware
Moderate
about 1 year ago
Shopware race condition bypasses voucher restrictions
packagist
shopware/platform
Low
over 1 year ago
Shopware default newsletter opt-in settings allow for mass sign-up abuse
packagist
shopware/platform, shopware/core
Moderate
over 1 year ago
Shopware Broken ACL on Document retrieval to access other customers documents
packagist
shopware/platform, shopware/core
High
over 1 year ago
Shopware Vulnerable to Blind SQL-injection in DAL aggregations
packagist
shopware/platform, shopware/core
High
over 1 year ago
Shopware allows Denial Of Service via password length
packagist
shopware/platform, shopware/core
Moderate
over 1 year ago
Shopware 6 allows attackers to check for registered accounts through the store-api
packagist
shopware/platform, shopware/core
Moderate
about 2 years ago
Shopware vulnerable to blind SQL-injection in DAL aggregations
packagist
shopware/core, shopware/platform
High
about 2 years ago
Shopware vulnerable to Server Side Template Injection in Twig using Context functions
packagist
shopware/core, shopware/platform
Potential
High
about 2 years ago
Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
packagist
shopware/core
Moderate
about 2 years ago
Shopware vulnerable to Improper Access Control with ManyToMany associations in store-api
packagist
shopware/platform, shopware/core
Moderate
over 2 years ago
Shopware Improper Session Handling in store-api account logout
packagist
shopware/platform, shopware/core
High
over 2 years ago
Shopware's session is persistent in Cache for 404 pages
packagist
shopware/platform, shopware/storefront
Moderate
over 2 years ago
Broken Access Control order API in Shopware
packagist
shopware/platform, shopware/core
Critical
over 2 years ago
Blind SQL injection in shopware
packagist
shopware/platform, shopware/core
Potential
Moderate
about 3 years ago
Shopware improper mail validation vulnerability
packagist
shopware/shopware
Potential
High
over 3 years ago
Shopware Has Improper Control of Generation of Code in Twig rendered views
packagist
shopware/core, shopware/platform
Moderate
over 3 years ago
Shopware has Improper Input Validation issue in newsletter subscription
packagist
shopware/core, shopware/platform
Low
over 3 years ago
Shopware has Insufficient Session Expiration in Administration
packagist
shopware/core, shopware/platform
Low
over 3 years ago
Shopware's log module vulnerable to Improper Output Neutralization
packagist
shopware/core, shopware/platform
Critical
over 3 years ago
Shopware vulnerable to Improper Control of Generation of Code in Twig rendered views
packagist
shopware/core, shopware/platform
Moderate
over 3 years ago
Shopware vulnerable to Improper Input Validation of Clearance sale in cart
packagist
shopware/core, shopware/platform
Potential
Moderate
almost 4 years ago
Shopware contains sensitive data in backend customer module
packagist
shopware/shopware
Potential
Moderate
almost 4 years ago
Shopware access control list bypassed via crafted specific URLs
packagist
shopware/shopware
Potential
Moderate
about 4 years ago
Shopware vulnerable to persistent cross site scripting (XSS) in customer module
packagist
shopware/shopware
Potential
Moderate
about 4 years ago
Authenticated Stored Cross-site Scripting in Shopware
packagist
shopware/shopware
High
over 4 years ago
Shopware database password is leaked to an unauthenticated users
packagist
shopware/platform, shopware/core
Potential
Potential
Moderate
over 4 years ago
Multiple valid tokens for password reset in Shopware
packagist
shopware/shopware
Potential
Potential
Moderate
over 4 years ago
Reflected Cross-site Scripting in Shopware storefront
packagist
shopware/shopware
High
over 4 years ago
Improper Access Control in Shopware
packagist
shopware/core, shopware/platform
High
over 4 years ago
Server-Side Request Forgery (SSRF) in Shopware
packagist
shopware/core, shopware/platform
Moderate
over 4 years ago
HTTP caching is marking private HTTP headers as public in Shopware
packagist
shopware/storefront, shopware/core, shopware/platform
Moderate
over 4 years ago
HTML injection possibility in voucher code form in Shopware
packagist
shopware/storefront, shopware/core, shopware/platform
Low
over 4 years ago
Shopware user session is not logged out if the password is reset via password recovery
packagist
shopware/core, shopware/platform
Moderate
over 4 years ago
Shopware guest session is shared between customers
packagist
shopware/storefront, shopware/platform
Potential
Potential
Critical
almost 5 years ago
Webcache Poisoning in shopware/platform and shopware/core
packagist
shopware/platform, shopware/core
Potential
Moderate
almost 5 years ago
Authenticated Stored XSS in shopware/shopware
packagist
shopware/shopware
High
almost 5 years ago
Exposure of Sensitive Information to an Unauthorized Actor
packagist
shopware/platform
Moderate
almost 5 years ago
Exposure of Sensitive Information to an Unauthorized Actor
packagist
shopware/platform
Critical
almost 5 years ago
Exposure of Sensitive Information to an Unauthorized Actor
packagist
shopware/platform
Potential
Potential
Moderate
almost 5 years ago
Exposure of Sensitive Information to an Unauthorized Actor
packagist
shopware/shopware
Moderate
about 5 years ago
Insecure direct object reference of log files of the Import/Export feature
packagist
shopware/core, shopware/platform
High
about 5 years ago
Command injection in mail agent settings
packagist
shopware/core, shopware/platform
Moderate
about 5 years ago
Manipulation of product reviews via API
packagist
shopware/core, shopware/platform
High
about 5 years ago
Cross-Site Scripting via SVG media files
packagist
shopware/platform, shopware/core
High
about 5 years ago
Authenticated server-side request forgery in file upload via URL.
packagist
shopware/core, shopware/platform
Moderate
about 5 years ago
non-admin users can create integration role with administrator role
packagist
shopware/core, shopware/platform
Moderate
about 5 years ago
Internal hidden fields are visible on to many associations in admin api
packagist
shopware/core, shopware/platform
High
about 5 years ago
Private files publicly accessible with Cloud Storage providers
packagist
shopware/core, shopware/platform
Low
about 5 years ago
Creation of order credits was not validated by acl in admin orders
packagist
shopware/core, shopware/platform
Moderate
about 5 years ago
Canceling of orders not related to the logged-in user
packagist
shopware/core, shopware/platform
Potential
Potential
Critical
over 5 years ago
After order payment process manipulation in shopware/platform and shopware/core
packagist
shopware/core, shopware/platform
Critical
over 5 years ago
Leak of information via Store-API aggregations in shopware/platform and shopware/core
packagist
shopware/platform, shopware/core
Low
over 5 years ago
Authenticated Server Side Request Forgery
packagist
shopware/core, shopware/platform
Low
over 5 years ago
Information exposure via query strings in URL
packagist
shopware/core, shopware/platform
Potential
Potential
Potential
Low
almost 6 years ago
Denial of Service via Cache Flooding
packagist
shopware/core, shopware/platform
Moderate
almost 6 years ago
Authenticated XML External Entity Processing
packagist
shopware/core, shopware/platform
Low
almost 6 years ago
Non-persistent XSS in the Storefront in Shopware
packagist
shopware/core, shopware/platform
Low
almost 6 years ago
RCE in Third Party Library in Shopware
packagist
shopware/core, shopware/platform