SQL injection in Shopware - #VU145364

 

SQL injection in Shopware - #VU145364

Published: August 25, 2026


Vulnerability identifier: #VU145364
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary SQL commands.

The vulnerability exists due to SQL injection in custom-entity definitions in the app manifest when processing custom entity field names supplied by apps. A remote privileged user can supply a crafted custom-entity definition to execute arbitrary SQL commands.

Exploitation may allow reading, modifying, or deleting shop data, altering the database schema, or disrupting the shop.


Affected software

Shopware

Remediation

Install security update from vendor's website.

Shopware - addressed in versions 6.6.10.23, 6.7.13.1

External References

Related Security Bulletins