Vulnerabilidades en Shopware
65 resultadosAnálisis Vexday
Shopware apresenta apenas 1 CVE catalogada na base, sem incidentes sob ataque ativo ou críticos em exploração. A vulnerabilidade, relacionada a condições de corrida (CWE-362), não foi divulgada recentemente, indicando um perfil de risco baixo e estável no momento.
CVE-2024-31447MEDIUMShopware has Improper Session Handling in store-apiEPSS 0.5%CVE-2022-24744LOWInsufficient Session Expiration in shopwareEPSS 0.5%CVE-2024-42354MEDIUMShopware vulnerable to Improper Access Control with ManyToMany associations in store-apiEPSS 0.4%CVE-2026-23498HIGHShopware Improper Control of Generation of Code in Twig rendered viewsEPSS 0.4%CVE-2024-22407MEDIUMBroken Access Control order API in ShopwareEPSS 0.4%CVE-2025-30151HIGHShopware allows Denial Of Service via password lengthEPSS 0.4%CVE-2025-7954MEDIUMRace Condition in Shopware Voucher SubmissionEPSS 0.4%CVE-2025-30150MEDIUMShopware 6 allows attackers to check for registered accounts through the store-apiEPSS 0.4%CVE-2024-22408HIGHServer-Side Request Forgery (SSRF) in Shopware Flow BuilderEPSS 0.4%CVE-2023-23941HIGHSwagPayPal payment not sent to PayPal correctlyEPSS 0.3%CVE-2025-32378MEDIUMShopware's default newsletter opt-in settings allow for mass sign-up abuseEPSS 0.3%CVE-2026-48015MEDIUMShopware: Stored XSS via SVG file upload — no SVG sanitizationEPSS 0.3%CVE-2026-48009MEDIUMShopware: Admin Account Takeover via User Recovery Hash ExposureEPSS 0.3%CVE-2026-31889HIGHShopware has a potential take over of app credentialsEPSS 0.3%CVE-2026-48010MEDIUMShopware: Privilege escalation: non-admin user with user:create ACL can create admin accountsEPSS 0.3%CVE-2026-48008MEDIUMShopware: Privilege Escalation via Sync API Integration Admin Flag BypassEPSS 0.3%CVE-2026-48016MEDIUMShopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-paymentEPSS 0.2%CVE-2026-31887HIGHShopware unauthenticated data extraction possible through store-api.order endpointEPSS 0.2%CVE-2026-48014MEDIUMShopware: Admin API ACL Bypass in Order State Transition EndpointsEPSS 0.2%CVE-2026-48011LOWShopware: Timing-attack on admin panel allowing enumeration of administrator usernamesEPSS 0.2%