CVE Tools

Shopware/core

56 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Shopware/core, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Shopware/core CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Shopware/core CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-045
2025-050
2025-060
2025-070
2025-080
2025-091
2025-105
2025-111
2025-120
2026-011
2026-020
2026-033
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 56 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical26%
  • High1442%
  • Medium1442%
  • Low39%

Latest CVEs

The 15 most recently published vulnerabilities affecting Shopware/core.

  1. CVE-2026-31889Shopware has a potential take over of app credentials8.9
  2. CVE-2026-31888Shopware has user enumeration via distinct error codes on Store API login endpoint5.3
  3. CVE-2026-31887Shopware unauthenticated data extraction possible through store-api.order endpoint7.5
  4. CVE-2026-23498Shopware Improper Control of Generation of Code in Twig rendered views7.2
  5. GHSA-2w46-vq8h-98vhShopware 6's password recovery link does not expire after email change—
  6. GHSA-r2vg-hvjm-fg38Shopware Customer Orders can be canceled, even if refunds are disabled—
  7. GHSA-27c9-vp3w-6ww8Shopware exposes sensitive user information via CSV export mapping—
  8. GHSA-3cpp-fv95-mpr5Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice—
  9. GHSA-6wh5-mw9h-5c3wShopware vulnerable to path traversal via Plugin upload—
  10. GHSA-m895-2hj3-8cg9Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually—
  11. GHSA-9v82-vcjx-m76jShopware: Reflective Cross Site-Scripting (XSS) in CMS components—
  12. CVE-2025-27892Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.6.8
  13. CVE-2025-32378Shopware's default newsletter opt-in settings allow for mass sign-up abuse5.3
  14. GHSA-68wv-g3fw-pq7qShopware Broken ACL on Document retrieval to access other customers documents—
  15. CVE-2025-30150Shopware 6 allows attackers to check for registered accounts through the store-api5.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store