non-admin users can create integration role with administrator role
Modified: 12/2/2024
package
pkg:packagist/shopware/platform
non-admin users can create integration role with administrator role
Modified: 12/2/2024
Shopware exposes sensitive user information via CSV export mapping
Modified: 9/10/2026
Shopware race condition bypasses voucher restrictions
Modified: 9/10/2026
Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
Modified: 8/12/2024
Exposure of Sensitive Information to an Unauthorized Actor
Modified: 9/10/2026
Shopware vulnerable to Server Side Template Injection in Twig using Context functions
Modified: 8/12/2024
Broken Access Control order API in Shopware
Modified: 9/10/2026
Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice
Modified: 9/10/2026
Shopware has Improper Input Validation issue in newsletter subscription
Modified: 9/10/2026
Shopware default newsletter opt-in settings allow for mass sign-up abuse
Modified: 9/10/2025
Shopware SSO referer trust leading to an arbitrary redirect target
Modified: 9/10/2026
Shopware Improper Session Handling in store-api account logout
Modified: 9/10/2026
Insecure direct object reference of log files of the Import/Export feature
Modified: 9/10/2026
Shopware has Insufficient Session Expiration in Administration
Modified: 9/10/2026
Authenticated Privilege Escalation
Modified: 12/2/2024
Shopware vulnerable to SSRF
Modified: 2/16/2024
Exposure of Sensitive Information to an Unauthorized Actor
Modified: 9/10/2026
Shopware Broken ACL on Document retrieval to access other customers documents
Modified: 4/8/2025
Exposure of Sensitive Information to an Unauthorized Actor
Modified: 9/10/2026
Shopware vulnerable to path traversal via Plugin upload
Modified: 9/10/2026
HTTP caching is marking private HTTP headers as public in Shopware
Modified: 2/16/2024
Shopware's log module vulnerable to Improper Output Neutralization
Modified: 9/10/2026
Server-Side Request Forgery (SSRF) in Shopware
Modified: 11/8/2023
Shopware Has Improper Control of Generation of Code in Twig rendered views
Modified: 9/10/2026
Shopware: Unauthenticated data extraction possible through store-api.order endpoint
Modified: 9/10/2026
Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames
Modified: 9/10/2026
After order payment process manipulation in shopware/platform and shopware/core
Modified: 12/2/2024
Shopware Vulnerable to Blind SQL-injection in DAL aggregations
Modified: 5/12/2025
Authenticated Server Side Request Forgery
Modified: 12/2/2024
Shopware vulnerable to Improper Input Validation of Clearance sale in cart
Modified: 11/8/2023
Shopware: Admin Account Takeover via User Recovery Hash Exposure
Modified: 9/10/2026
Authenticated XML External Entity Processing
Modified: 12/2/2024
Shopware vulnerable to Improper Control of Generation of Code in Twig rendered views
Modified: 11/8/2023
HTML injection possibility in voucher code form in Shopware
Modified: 11/8/2023
Manipulation of product reviews via API
Modified: 9/10/2026
Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment
Modified: 9/10/2026
Improper Access Control in Shopware
Modified: 11/8/2023
Shopware's session is persistent in Cache for 404 pages
Modified: 2/22/2026
Shopware vulnerable to a potential take over of app credentials
Modified: 9/10/2026
Shopware allows Denial Of Service via password length
Modified: 4/8/2025
Information exposure via query strings in URL
Modified: 12/2/2024
Leak of information via Store-API
Modified: 9/10/2026
Shopware: Admin API ACL Bypass in Order State Transition Endpoints
Modified: 9/10/2026
Cross-Site Scripting via SVG media files
Modified: 9/10/2026
Shopware vulnerable to Cross-site Scripting
Modified: 2/16/2024
Creation of order credits was not validated by acl in admin orders
Modified: 9/10/2026
Authenticated server-side request forgery in file upload via URL.
Modified: 9/10/2026
Internal hidden fields are visible on to many associations in admin api
Modified: 9/10/2026
Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation
Modified: 9/10/2026
Shopware has user enumeration via distinct error codes on Store API login endpoint
Modified: 9/10/2026
Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass
Modified: 9/10/2026
Potential Session Hijacking
Modified: 9/10/2026
Shopware 6 allows attackers to check for registered accounts through the store-api
Modified: 9/10/2025
Shopware vulnerable to Improper Access Control with ManyToMany associations in store-api
Modified: 8/12/2024
Shopware guest session is shared between customers
Modified: 11/8/2023
Generation of fake documents via public GET-call
Modified: 12/2/2024
Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually
Modified: 9/10/2026
Denial of Service via Cache Flooding
Modified: 12/2/2024
Missing Authentication for Critical Function
Modified: 9/10/2026
Shopware vulnerable to blind SQL-injection in DAL aggregations
Modified: 11/28/2024
Authenticated remote code execution
Modified: 12/2/2024
Leak of information via Store-API aggregations in shopware/platform and shopware/core
Modified: 12/2/2024
Blind SQL injection in shopware
Modified: 9/10/2026
RCE in Third Party Library in Shopware
Modified: 12/2/2024
Non-persistent XSS in the Storefront in Shopware
Modified: 12/2/2024
Shopware Customer Orders can be canceled, even if refunds are disabled
Modified: 9/10/2026
Shopware database password is leaked to an unauthenticated users
Modified: 7/8/2024
Webcache Poisoning in shopware/platform and shopware/core
Modified: 12/2/2024
Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts
Modified: 9/10/2026
Private files publicly accessible with Cloud Storage providers
Modified: 9/10/2026
Shopware user session is not logged out if the password is reset via password recovery
Modified: 11/8/2023
Canceling of orders not related to the logged-in user
Modified: 12/2/2024
Command injection in mail agent settings
Modified: 9/10/2026
Shopware: Stored XSS via SVG file upload — no SVG sanitization
Modified: 9/10/2026