shopware
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 71 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 8, 2016 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →shopware/commercial: `/api/_info/config` route exposes information about licenses
swag/platform-security: `/api/_info/config` route exposes information about licenses and active security fixes
Shopware has a potential take over of app credentials
Shopware has user enumeration via distinct error codes on Store API login endpoint
Shopware unauthenticated data extraction possible through store-api.order endpoint
Shopware Improper Control of Generation of Code in Twig rendered views
Shopware's inproper input validation can lead to Reflected XSS through Storefront Login Page
Race Condition in Shopware Voucher Submission
Shopware's default newsletter opt-in settings allow for mass sign-up abuse
Monitor shopware in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.