Vulnerabilidades en shopware

65 resultados
Análisis Vexday

Com 56 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo catálogo KEV da CISA, o Shopware apresenta taxa de exploração abaixo da média geral do catálogo. Das vulnerabilidades registradas, três são classificadas como críticas e nenhuma possui prova de conceito pública disponível, o que reduz — mas não elimina — o risco imediato de exploração massiva. A falha mais comum é do tipo CWE-200 (exposição indevida de informações), e a CVE de maior relevância no momento, CVE-2021-37708, registra escore EPSS de 0,0236, indicando probabilidade baixa de exploração ativa no curto prazo. O baixo volume de novas CVEs nos últimos 90 dias e a ausência de PoCs públicas sugerem superfície de ataque relativamente estável, mas as três falhas críticas merecem atenção prioritária nos ciclos de patching.

CVE-2021-41188MEDIUMAuthenticated Stored XSS in AdministrationEPSS 0.8%CVE-2022-24748MEDIUMIncorrect Authentication in shopwareEPSS 0.8%CVE-2021-37710HIGHCross-Site Scripting via SVG media filesEPSS 0.7%CVE-2021-32713MEDIUMAuthenticated Stored XSSEPSS 0.7%CVE-2023-22732LOWInsufficient Session Expiration in Administration in shopwareEPSS 0.7%CVE-2023-22733LOWImproper Output Neutralization in Log Module in shopwareEPSS 0.7%CVE-2022-31057MEDIUMAuthenticated Stored XSS in Shopware AdministrationEPSS 0.7%CVE-2022-36101MEDIUMSensitive data in backend customer moduleEPSS 0.7%CVE-2022-31148MEDIUMPersistent cross site scripting in customer module in ShopwareEPSS 0.7%CVE-2023-22730MEDIUMImproper Input Validation of Clearance sale in cartEPSS 0.7%CVE-2023-34099MEDIUMImproper mail validation in ShopwareEPSS 0.6%CVE-2024-42356HIGHShopware vulnerable to Server Side Template Injection in Twig using Context functionsEPSS 0.6%CVE-2024-22406CRITICALBlind SQL-injection in DAL aggregations in ShopwareEPSS 0.6%CVE-2021-32709MEDIUMCreation of order credits was not validated by acl in admin ordersEPSS 0.6%CVE-2023-34098MEDIUMDependency configuration exposed in ShopwareEPSS 0.6%CVE-2024-27917HIGHShopware's session is persistent in Cache for 404 pagesEPSS 0.6%CVE-2022-24879HIGHMalfunction of Cross-Site Request Forgery token validationEPSS 0.6%CVE-2023-22734MEDIUMImproper Input Newsletter subscription option validation in shopwareEPSS 0.6%CVE-2024-42357HIGHShopware vulnerable to blind SQL-injection in DAL aggregationsEPSS 0.6%CVE-2022-24745MEDIUMGuest session is shared between customers in shopwareEPSS 0.5%