Cross-site scripting in Shopware - #VU131903
Published: May 20, 2026
Shopware
Detailed vulnerability description
The vulnerability allows a remote attacker to execute malicious script in the victim's browser session.
The vulnerability exists due to cross-site scripting in the activeRouteParameters JavaScript variable in CMS components when handling crafted URLs at the /page/cms/* and /widget/cms/* endpoints. A remote attacker can inject malicious JavaScript code into a URL to execute malicious script in the victim's browser session.
User interaction is required to visit a crafted URL.