SQL injection in Shopware - #VU150742
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose arbitrary data from the underlying database.
The vulnerability exists due to insufficient input validation in Store API aggregation handling when processing Store API aggregation input. A remote attacker can send specially crafted aggregation input to disclose arbitrary data from the underlying database.
The issue requires PHP versions before 8.4 with PDO MySQL emulated prepares enabled.