Vulnerabilidades en shopware

65 resultados
Análisis Vexday

Com 56 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo catálogo KEV da CISA, o Shopware apresenta taxa de exploração abaixo da média geral do catálogo. Das vulnerabilidades registradas, três são classificadas como críticas e nenhuma possui prova de conceito pública disponível, o que reduz — mas não elimina — o risco imediato de exploração massiva. A falha mais comum é do tipo CWE-200 (exposição indevida de informações), e a CVE de maior relevância no momento, CVE-2021-37708, registra escore EPSS de 0,0236, indicando probabilidade baixa de exploração ativa no curto prazo. O baixo volume de novas CVEs nos últimos 90 dias e a ausência de PoCs públicas sugerem superfície de ataque relativamente estável, mas as três falhas críticas merecem atenção prioritária nos ciclos de patching.

CVE-2024-31447MEDIUMShopware has Improper Session Handling in store-apiEPSS 0.5%CVE-2022-24744LOWInsufficient Session Expiration in shopwareEPSS 0.5%CVE-2026-48015MEDIUMShopware: Stored XSS via SVG file upload — no SVG sanitizationEPSS 0.5%CVE-2026-48010MEDIUMShopware: Privilege escalation: non-admin user with user:create ACL can create admin accountsEPSS 0.5%CVE-2026-48008MEDIUMShopware: Privilege Escalation via Sync API Integration Admin Flag BypassEPSS 0.5%CVE-2026-48009MEDIUMShopware: Admin Account Takeover via User Recovery Hash ExposureEPSS 0.5%CVE-2026-23498HIGHShopware Improper Control of Generation of Code in Twig rendered viewsEPSS 0.4%CVE-2024-42354MEDIUMShopware vulnerable to Improper Access Control with ManyToMany associations in store-apiEPSS 0.4%CVE-2026-48016MEDIUMShopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-paymentEPSS 0.4%CVE-2025-30151HIGHShopware allows Denial Of Service via password lengthEPSS 0.4%CVE-2024-22407MEDIUMBroken Access Control order API in ShopwareEPSS 0.4%CVE-2025-30150MEDIUMShopware 6 allows attackers to check for registered accounts through the store-apiEPSS 0.4%CVE-2026-48014MEDIUMShopware: Admin API ACL Bypass in Order State Transition EndpointsEPSS 0.4%CVE-2025-7954MEDIUMRace Condition in Shopware Voucher SubmissionEPSS 0.4%CVE-2026-48013MEDIUMShopware: SSRF in Media External-Link Endpoint Bypasses IP ValidationEPSS 0.4%CVE-2024-22408HIGHServer-Side Request Forgery (SSRF) in Shopware Flow BuilderEPSS 0.4%CVE-2025-32378MEDIUMShopware's default newsletter opt-in settings allow for mass sign-up abuseEPSS 0.3%CVE-2023-23941HIGHSwagPayPal payment not sent to PayPal correctlyEPSS 0.3%CVE-2026-48012MEDIUMShopware SSO referer trust leading to an arbitrary redirect targetEPSS 0.3%CVE-2026-31889HIGHShopware has a potential take over of app credentialsEPSS 0.3%