Shopware platform is the core for all Shopware ecommerce products.
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-48013 shopware/core is vulnerable to Server-Side Request Forgery (SSRF) in versions 6.7.0.0 - 6.7.10.1. | 6.7.0.0 - 6.7.10.1 | Medium |
CVE-2026-48015 shopware/core is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.7.0.0 - 6.7.10.1 and 0.0.0 - 6.6.10.18. | 0.0.0 - 6.6.10.186.7.0.0 - 6.7.10.1 | Medium |
CVE-2026-48012 shopware/core is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 6.7.3.0 - 6.7.10.1. | 6.7.3.0 - 6.7.10.1 | Medium |
CVE-2026-31887 shopware/core is vulnerable to Incorrect Authorization in versions 6.7.0.0 - 6.7.8.1 and 0.0.0 - 6.6.10.15. | 0.0.0 - 6.6.10.156.7.0.0 - 6.7.8.1 | High |
CVE-2025-32378 shopware/core is vulnerable to Improper Control of Interaction Frequency in versions 6.6.0.0-rc1 - 6.6.10.3, 6.7.0.0-rc1 - 6.7.0.0-rc2 and 0.0.0 - 6.5.8.17. | 0.0.0 - 6.5.8.176.6.0.0-rc1 - 6.6.10.36.7.0.0-rc1 - 6.7.0.0-rc2 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.0 | — | — |
psr/cache Version ^3.0.0 | — | — |
twig/twig Version ^3.26.0 | — | — |
nyholm/psr7 Version ^1.5 | — | — |
ramsey/uuid Version ^4.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant