Exposição de Shopware

Ecommerce
39
score de exposição
7.406
sites usam
0
em exploração
1
críticos
Análise Vexday

O histórico de vulnerabilidades do Shopware reúne 30 CVEs catalogadas, com uma única entrada de severidade crítica e nenhum registro no catálogo CISA KEV, taxa que se mantém abaixo da média geral do catálogo. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que indica atenção persistente a controles de saída e validação de entrada nas superfícies web da plataforma. A CVE mais relevante no momento, CVE-2021-32712, apresenta EPSS de 0,0114, sugerindo probabilidade de exploração relativamente baixa no curto prazo, embora seu perfil crítico justifique acompanhamento contínuo. A presença de uma CVE surgida nos últimos 90 dias reforça que o processo de descoberta de falhas segue ativo, exigindo ciclos regulares de atualização e revisão de configuração por parte das equipes que operam a plataforma.

CVEs

38 resultados
CVE-2024-42354MEDIUMShopware vulnerable to Improper Access Control with ManyToMany associations in store-apiEPSS 0.4%CVE-2026-23498HIGHShopware Improper Control of Generation of Code in Twig rendered viewsEPSS 0.4%CVE-2024-22407MEDIUMBroken Access Control order API in ShopwareEPSS 0.4%CVE-2025-30151HIGHShopware allows Denial Of Service via password lengthEPSS 0.4%CVE-2025-7954MEDIUMRace Condition in Shopware Voucher SubmissionEPSS 0.4%CVE-2025-30150MEDIUMShopware 6 allows attackers to check for registered accounts through the store-apiEPSS 0.4%CVE-2024-22408HIGHServer-Side Request Forgery (SSRF) in Shopware Flow BuilderEPSS 0.4%CVE-2025-32378MEDIUMShopware's default newsletter opt-in settings allow for mass sign-up abuseEPSS 0.3%CVE-2026-48015MEDIUMShopware: Stored XSS via SVG file upload — no SVG sanitizationEPSS 0.3%CVE-2026-48009MEDIUMShopware: Admin Account Takeover via User Recovery Hash ExposureEPSS 0.3%CVE-2026-48008MEDIUMShopware: Privilege Escalation via Sync API Integration Admin Flag BypassEPSS 0.3%CVE-2026-48010MEDIUMShopware: Privilege escalation: non-admin user with user:create ACL can create admin accountsEPSS 0.3%CVE-2026-48016MEDIUMShopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-paymentEPSS 0.2%CVE-2026-48014MEDIUMShopware: Admin API ACL Bypass in Order State Transition EndpointsEPSS 0.2%CVE-2026-48011LOWShopware: Timing-attack on admin panel allowing enumeration of administrator usernamesEPSS 0.2%CVE-2026-48013MEDIUMShopware: SSRF in Media External-Link Endpoint Bypasses IP ValidationEPSS 0.2%CVE-2025-67648HIGHShopware's inproper input validation can lead to Reflected XSS through Storefront Login PageEPSS 0.2%CVE-2026-48012MEDIUMShopware SSO referer trust leading to an arbitrary redirect targetEPSS 0.2%