SQL injection in Shopware - #VU150742

 

SQL injection in Shopware - #VU150742

Published: September 17, 2026


Vulnerability identifier: #VU150742
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose arbitrary data from the underlying database.

The vulnerability exists due to insufficient input validation in Store API aggregation handling when processing Store API aggregation input. A remote attacker can send specially crafted aggregation input to disclose arbitrary data from the underlying database.

The issue requires PHP versions before 8.4 with PDO MySQL emulated prepares enabled.


Affected software

Shopware

Remediation

Install security update from vendor's website.

Shopware - addressed in versions 6.6.10.25, 6.7.14.1

External References

Related Security Bulletins