VDB
Sign up

package

Packagist/shopware/core

pkg:packagist/shopware/core

MEDIUMPackagist
GHSA-243q-g9j3-qf6r

non-admin users can create integration role with administrator role

Modified: 12/2/2024

MEDIUM4.9Packagist
GHSA-27c9-vp3w-6ww8

Shopware exposes sensitive user information via CSV export mapping

Modified: 9/10/2026

MEDIUM5.0Packagist
GHSA-2w46-vq8h-98vh

Shopware 6's password recovery link does not expire after email change

Modified: 9/10/2026

LOW2.7Packagist
GHSA-3cpp-fv95-mpr5

Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice

Modified: 9/10/2026

MEDIUM4.0Packagist
GHSA-68wv-g3fw-pq7q

Shopware Broken ACL on Document retrieval to access other customers documents

Modified: 4/8/2025

LOW2.7Packagist
GHSA-6wh5-mw9h-5c3w

Shopware vulnerable to path traversal via Plugin upload

Modified: 9/10/2026

CRITICALPackagist
GHSA-88rc-3p98-rgvx

After order payment process manipulation in shopware/platform and shopware/core

Modified: 12/2/2024

MEDIUM5.6Packagist
GHSA-8xv9-qcr9-ww9j

Authenticated XML External Entity Processing

Modified: 12/2/2024

HIGH8.8Packagist
GHSA-9v82-vcjx-m76j

Shopware: Reflective Cross Site-Scripting (XSS) in CMS components

Modified: 9/10/2025

LOWPackagist
GHSA-cq6h-w3mc-57f4

Information exposure via query strings in URL

Modified: 12/2/2024

MEDIUM5.3Packagist
GHSA-m895-2hj3-8cg9

Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually

Modified: 9/10/2026

CRITICALPackagist
GHSA-qg7c-q3vq-rgxr

Leak of information via Store-API aggregations in shopware/platform and shopware/core

Modified: 12/2/2024

LOWPackagist
GHSA-qvhr-55hg-3qwv

Non-persistent XSS in the Storefront in Shopware

Modified: 12/2/2024

MEDIUM4.3Packagist
GHSA-r2vg-hvjm-fg38

Shopware Customer Orders can be canceled, even if refunds are disabled

Modified: 9/10/2026

CRITICALPackagist
GHSA-r64m-qchj-hrjp

Webcache Poisoning in shopware/platform and shopware/core

Modified: 12/2/2024

MEDIUMPackagist
GHSA-wq3r-jwrq-xg6w

Canceling of orders not related to the logged-in user

Modified: 12/2/2024