pkg:Packagist/shopware/shopware

共 23 筆 CVECRITICAL1HIGH5MEDIUM16LOW1

✅ 檢查你的版本

所有已知漏洞

  • CRITICAL9.8CVE-2016-3109Shopware RCE Vulnerability
    from 0, < 4.3.7
  • HIGH8.8CVE-2019-12799Shopware Insecure Deserialization Vulnerability
    >= 5.3.0, <= 5.6.0
  • HIGH8.8CVE-2018-20713Shopware SQL Injection
    from 0, < 5.4.3
  • HIGH7.5CVE-2022-24879Malfunction of CSRF token validation in Shopware
    >= 5.2.0, < 5.7.9
  • HIGH7.2CVE-2026-23498Shopware Has Improper Control of Generation of Code in Twig rendered views
    >= 6.7.0.0, < 6.7.6.1
  • HIGH7.1CVE-2025-67648Shopware Storefront Reflected XSS in Storefront Login Page
    >= 6.4.6.0, < 6.6.10.10
  • MEDIUM6.8CVE-2022-21651Open redirect in shopware
    >= 5.0.0, < 5.7.7
  • MEDIUM6.5CVE-2017-18357Shopware XXE Vulnerability
    from 0, < 5.3.4
  • MEDIUM6.4CVE-2022-24892Multiple valid tokens for password reset in Shopware
    >= 5.0.4, < 5.7.9
  • MEDIUM6.3CVE-2022-36102Shopware access control list bypassed via crafted specific URLs
    from 0, < 5.7.15
  • MEDIUM6.1CVE-2022-48150Shopware vulnerable to cross-site scripting (XSS)
    from 0, <= 5.5.10
  • MEDIUM6.1CVE-2019-12935Shopware Cross-site Scripting Vulnerability
    from 0, < 5.5.8
  • MEDIUM6.1CVE-2017-15374Shopware XSS Vulnerability
    >= 5.2.5, <= 5.3
  • MEDIUM5.7CVE-2021-41188Authenticated Stored XSS in shopware/shopware
    from 0, < 5.7.6
  • MEDIUM5.4CVE-2022-36101Shopware contains sensitive data in backend customer module
    from 0, < 5.7.15
  • MEDIUM5.4CVE-2022-31148Shopware vulnerable to persistent cross site scripting (XSS) in customer module
    >= 5.7.0, < 5.7.14
  • MEDIUM5.4CVE-2022-31057Authenticated Stored Cross-site Scripting in Shopware
    from 0, < 5.7.12
  • MEDIUM5.4CVE-2022-24873Reflected Cross-site Scripting in Shopware storefront
    from 0, < 5.7.9
  • MEDIUM5.3CVE-2023-34099Shopware improper mail validation vulnerability
    >= 5.1.4, < 5.7.18
  • MEDIUM5.3CVE-2023-34098Shopware dependency configuration exposed
    >= 5.6.0, < 5.7.18
  • MEDIUM5.3CVE-2021-32712Exposure of Sensitive Information to an Unauthorized Actor
    from 0, < 5.6.10
  • MEDIUM4.8CVE-2021-32713Cross-site scripting
    from 0, < 5.6.10
  • LOW3.5CVE-2022-21652Insufficient Session Expiration in shopware
    >= 5.7.3, < 5.7.7