CVE-2025-67648: high-severity vulnerability in shopware
Shopware's inproper input validation can lead to Reflected XSS through Storefront Login Page
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template of the Storefront login page without further processing or input validation. This allows direct code injection into the template via the URL parameter, waitTime, which lacks proper input validation. This issue is fixed in versions 6.6.10.10 and 6.7.5.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Affected products
shopware · shopwareRelated CVEs — shopware
In the same product, most dangerous first.
CVE-2021-32712MEDIUMInformation leakage in Error HandlerEPSS 1.1%CVE-2022-24892MEDIUMMultiple valid tokens for password reset in ShopwareEPSS 0.9%CVE-2024-42355HIGHShopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagEPSS 0.9%CVE-2022-36102MEDIUMAcess control list bypassed via crafted specific URLsEPSS 0.8%CVE-2022-21652LOWInsufficient Session Expiration in shopwareEPSS 0.8%CVE-2022-24873MEDIUMNon-Stored Cross-site Scripting in Shopware storefrontEPSS 0.8%