SQL injection in Shopware - #VU145364
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary SQL commands.
The vulnerability exists due to SQL injection in custom-entity definitions in the app manifest when processing custom entity field names supplied by apps. A remote privileged user can supply a crafted custom-entity definition to execute arbitrary SQL commands.
Exploitation may allow reading, modifying, or deleting shop data, altering the database schema, or disrupting the shop.