Improper Neutralization of Special Elements Used in a Template Engine in Shopware - #VU145367
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary PHP functions and operating-system commands.
The vulnerability exists due to improper neutralization of special elements used in a template engine in the App Script sandbox when processing app scripts. A remote attacker can install and activate a malicious or compromised App to execute arbitrary PHP functions and operating-system commands.
User interaction is required to trigger exploitation.