SQL injection in Shopware - CVE-2025-27892
Published: April 8, 2025 / Updated: May 20, 2026
Shopware
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information, modify data, or cause a denial of service.
The vulnerability exists due to sql injection in the DAL aggregations name field in nested aggregations when processing search requests with user-supplied aggregation parameters. A remote attacker can send specially crafted aggregation parameters to disclose sensitive information, modify data, or cause a denial of service.
The issue affects the search functionality exposed through the application API.