Loading HuntDB...

shopware

3 Products 46 CVEs

CVE Severity Distribution (All Time)

Critical
3
High
13
Medium
26
Low
4

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-42357 HIGH 1 year, 3 months ago

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which ena…

CVE-2024-42356 HIGH 1 year, 3 months ago

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and a…

CVE-2024-42355 HIGH 1 year, 3 months ago

Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Pr…

CVE-2024-42354 MEDIUM 1 year, 3 months ago

Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be mark…

CVE-2024-31447 MEDIUM 1 year, 7 months ago

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, wh…

CVE-2024-27917 HIGH 1 year, 8 months ago

Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the R…

CVE-2024-22406 CRITICAL 1 year, 10 months ago

Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through in…

CVE-2024-22407 MEDIUM 1 year, 10 months ago

Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations fo…

CVE-2024-22408 HIGH 1 year, 10 months ago

Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate t…

CVE-2023-34099 MEDIUM 2 years, 4 months ago

Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it was possible to construct diffe…