Known vulnerabilities in Shopware Shopware

Vendor: Shopware
Website: https://www.shopware.com/en/
Total Security Bulletins: 21

Security bulletins (21)

Secuity bulletin Severity Status Published
SB2026011975: Authenticated server-side template injection in Shopware Low
Patched
19.01.2026
SB20251210213: Reflected XSS in Shopware login page Medium
Patched
10.12.2025
SB2025102431: Multiple vulnerabilities in Shopware Medium
Patched
24.10.2025
SB2024042308: Insufficient Session Expiration in Shopware Medium
Patched
23.04.2024
SB2024030836: Session cookie disclosure in Shopware High
Patched
08.03.2024
SB2024011713: Multiple vulnerabilities in Shopware High
Patched
17.01.2024
SB2023062810: Multiple vulnerabilities in Shopware Medium
Patched
28.06.2023
SB2022050212: Multiple vulnerabilities in Shopware Medium
Patched
02.05.2022
SB2022042208: Multiple vulnerabilities in Shopware Medium
Patched
22.04.2022
SB2021081906: Multiple vulnerabilities in Shopware High
Patched
19.08.2021
SB2021070210: Information disclosure in Shopware Medium
Patched
02.07.2021
SB2021070209: Information disclosure in Shopware Medium
Patched
02.07.2021
SB2021070208: Multiple vulnerabilities in Shopware Medium
Patched
02.07.2021
SB2021062808: Multiple vulnerabilities in Shopware Medium
Patched
28.06.2021
SB2020112321: Cross-site scripting in Shopware Low
Patched
23.11.2020
SB2020080404: Multiple vulnerabilities in Shopware Medium
Patched
04.08.2020
SB2019062604: Cross-site scripting in Shopware Low
Patched
26.06.2019
SB2019060412: Cross-site scripting in Shopware Shopware Medium
Patched
04.06.2019
SB2019011513: Externally Controlled Reference to a Resource in Another Sphere in Shopware Shopware Medium
Patched
15.01.2019
SB2019011514: SQL injection in Shopware Shopware High
Patched
15.01.2019


Showing elements 1 - 20 out of 21