Shopware/core
56 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Shopware/core, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Shopware/core CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 5 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 1 |
| 2025-10 | 5 |
| 2025-11 | 1 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 3 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 56 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High14
- Medium14
- Low3
Latest CVEs
The 15 most recently published vulnerabilities affecting Shopware/core.
- CVE-2026-31889Shopware has a potential take over of app credentials8.9
- CVE-2026-31888Shopware has user enumeration via distinct error codes on Store API login endpoint5.3
- CVE-2026-31887Shopware unauthenticated data extraction possible through store-api.order endpoint7.5
- CVE-2026-23498Shopware Improper Control of Generation of Code in Twig rendered views7.2
- GHSA-2w46-vq8h-98vhShopware 6's password recovery link does not expire after email change—
- GHSA-r2vg-hvjm-fg38Shopware Customer Orders can be canceled, even if refunds are disabled—
- GHSA-27c9-vp3w-6ww8Shopware exposes sensitive user information via CSV export mapping—
- GHSA-3cpp-fv95-mpr5Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice—
- GHSA-6wh5-mw9h-5c3wShopware vulnerable to path traversal via Plugin upload—
- GHSA-m895-2hj3-8cg9Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually—
- GHSA-9v82-vcjx-m76jShopware: Reflective Cross Site-Scripting (XSS) in CMS components—
- CVE-2025-27892Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.6.8
- CVE-2025-32378Shopware's default newsletter opt-in settings allow for mass sign-up abuse5.3
- GHSA-68wv-g3fw-pq7qShopware Broken ACL on Document retrieval to access other customers documents—
- CVE-2025-30150Shopware 6 allows attackers to check for registered accounts through the store-api5.3
Product grouping is registry-driven, with AI assist and human review. How it works