Where
-Infinity
0

Shopware ShopwareSQL Injection

Risk 51
Severity
7.3
First published (updated )

Shopware ShopwareShopware allows Denial Of Service via password length

Risk 43
Severity
7.5
First published (updated )

composer/shopware/coreShopware vulnerable to blind SQL-injection in DAL aggregations

Risk 89
Severity
9.8
First published (updated )

composer/shopware/coreShopware vulnerable to Server Side Template Injection in Twig using Context functions

Risk 72
Severity
8.3
First published (updated )

composer/shopware/coreShopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

Risk 89
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/shopware/platformShopware vulnerable to Improper Access Control with ManyToMany associations in store-api

Risk 37
Severity
5.9
First published (updated )

composer/shopware/shopwareXSS

Risk 38
Severity
6.1
First published (updated )

Shopware SwagPayPalSwagPayPal payment not sent to PayPal correctly

Risk 43
Severity
7.5
First published (updated )

Shopware ShopwareImproper Output Neutralization in Log Module in shopware

Risk 38
Severity
6.5
First published (updated )

Shopware ShopwareInsufficient Session Expiration in Administration in shopware

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Shopware ShopwareImproper Control of Generation of Code in Twig rendered views in shopware

Risk 83
Severity
10
First published (updated )

Shopware ShopwareImproper Input Validation of Clearance sale in cart

Risk 43
Severity
7.5
First published (updated )

Shopware ShopwareImproper Input Newsletter subscription option validation in shopware

Risk 43
Severity
7.5
First published (updated )

Shopware ShopwareAcess control list bypassed via crafted specific URLs

Risk 66
Severity
7.2
First published (updated )

Shopware ShopwareSensitive data in backend customer module

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Shopware ShopwarePersistent cross site scripting in customer module in Shopware

Risk 34
Severity
5.4
First published (updated )

Shopware ShopwareAuthenticated Stored XSS in Shopware Administration

Risk 46
Severity
6.5
First published (updated )

Shopware ShopwareMultiple valid tokens for password reset in Shopware

Risk 70
Severity
7.5
First published (updated )

Shopware ShopwareMalfunction of Cross-Site Request Forgery token validation

Risk 43
Severity
7.5
First published (updated )

Shopware ShopwareNon-Stored Cross-site Scripting in Shopware storefront

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Shopware ShopwareImproper Access Control in shopware

Risk 60
Severity
8.1
First published (updated )

Shopware ShopwareServer-Side Request Forgery (SSRF) in Shopware

Risk 66
Severity
7.2
First published (updated )

Shopware B2b Suite ShopwareSQL Injection

Risk 38
Severity
6.5
First published (updated )

Shopware ShopwareInsufficient Session Expiration in shopware

Risk 19
Severity
3.5
First published (updated )

Shopware ShopwareGuest session is shared between customers in shopware

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Shopware ShopwareHTML injection possibility in voucher code form

Risk 38
Severity
6.1
First published (updated )

Shopware ShopwareHTTP caching is marking private HTTP headers as public

Risk 37
Severity
6.3
First published (updated )

Shopware ShopwareIncorrect Authentication in shopware

Risk 43
Severity
7.5
First published (updated )

Shopware ShopwareInsufficient Session Expiration in shopware

Risk 60
Severity
8.1
First published (updated )

Shopware ShopwareOpen redirect in shopware

Risk 38
Severity
6.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203