CVE Tools

Shopware/platform

65 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Shopware/platform, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Shopware/platform CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Shopware/platform CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-045
2025-050
2025-060
2025-070
2025-081
2025-090
2025-105
2025-110
2025-120
2026-010
2026-020
2026-033
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 65 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical37%
  • High1741%
  • Medium1844%
  • Low37%

Latest CVEs

The 15 most recently published vulnerabilities affecting Shopware/platform.

  1. CVE-2026-31889Shopware has a potential take over of app credentials8.9
  2. CVE-2026-31888Shopware has user enumeration via distinct error codes on Store API login endpoint5.3
  3. CVE-2026-31887Shopware unauthenticated data extraction possible through store-api.order endpoint7.5
  4. GHSA-r2vg-hvjm-fg38Shopware Customer Orders can be canceled, even if refunds are disabled—
  5. GHSA-27c9-vp3w-6ww8Shopware exposes sensitive user information via CSV export mapping—
  6. GHSA-3cpp-fv95-mpr5Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice—
  7. GHSA-6wh5-mw9h-5c3wShopware vulnerable to path traversal via Plugin upload—
  8. GHSA-m895-2hj3-8cg9Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually—
  9. CVE-2025-7954Race Condition in Shopware Voucher Submission8.1
  10. CVE-2025-27892Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.6.8
  11. CVE-2025-32378Shopware's default newsletter opt-in settings allow for mass sign-up abuse5.3
  12. GHSA-68wv-g3fw-pq7qShopware Broken ACL on Document retrieval to access other customers documents—
  13. CVE-2025-30150Shopware 6 allows attackers to check for registered accounts through the store-api5.3
  14. CVE-2025-30151Shopware allows Denial Of Service via password length7.5
  15. CVE-2024-42357Shopware vulnerable to blind SQL-injection in DAL aggregations7.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store