Vulnerabilities in shopware

65 results
Vexday analysis

Com 56 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo catálogo KEV da CISA, o Shopware apresenta taxa de exploração abaixo da média geral do catálogo. Das vulnerabilidades registradas, três são classificadas como críticas e nenhuma possui prova de conceito pública disponível, o que reduz — mas não elimina — o risco imediato de exploração massiva. A falha mais comum é do tipo CWE-200 (exposição indevida de informações), e a CVE de maior relevância no momento, CVE-2021-37708, registra escore EPSS de 0,0236, indicando probabilidade baixa de exploração ativa no curto prazo. O baixo volume de novas CVEs nos últimos 90 dias e a ausência de PoCs públicas sugerem superfície de ataque relativamente estável, mas as três falhas críticas merecem atenção prioritária nos ciclos de patching.

CVE-2021-37708HIGHCommand injection in mail agent settingsEPSS 2.4%CVE-2021-32717HIGHPrivate files publicly accessible with Cloud Storage providersEPSS 1.5%CVE-2021-32711CRITICALLeak of information via Store-APIEPSS 1.4%CVE-2023-22731CRITICALImproper Control of Generation of Code in Twig rendered views in shopwareEPSS 1.3%CVE-2021-32712MEDIUMInformation leakage in Error HandlerEPSS 1.1%CVE-2021-32716MEDIUMInternal hidden fields are visible on to many associations in admin apiEPSS 1.1%CVE-2022-24747MEDIUMHTTP caching is marking private HTTP headers as publicEPSS 1.1%CVE-2021-37711HIGHAuthenticated server-side request forgery in file upload via URL.EPSS 1.1%CVE-2022-24871HIGHServer-Side Request Forgery (SSRF) in ShopwareEPSS 1.0%CVE-2022-24872HIGHImproper Access Control in shopwareEPSS 1.0%CVE-2021-37707MEDIUMManipulation of product reviews via APIEPSS 0.9%CVE-2021-32710MEDIUMPotential Session Hijacking in ShopwareEPSS 0.9%CVE-2024-42355HIGHShopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagEPSS 0.9%CVE-2022-24746MEDIUMHTML injection possibility in voucher code formEPSS 0.8%CVE-2022-24892MEDIUMMultiple valid tokens for password reset in ShopwareEPSS 0.8%CVE-2022-21652LOWInsufficient Session Expiration in shopwareEPSS 0.8%CVE-2021-37709MEDIUMInsecure direct object reference of log files of the Import/Export featureEPSS 0.8%CVE-2022-21651MEDIUMOpen redirect in shopwareEPSS 0.8%CVE-2022-24873MEDIUMNon-Stored Cross-site Scripting in Shopware storefrontEPSS 0.8%CVE-2022-24748MEDIUMIncorrect Authentication in shopwareEPSS 0.8%