Shopware platform is the core for all Shopware ecommerce products.
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-31887 New shopware/core is vulnerable to Incorrect Authorization in versions 6.7.0.0 - 6.7.8.1 and 0.0.0 - 6.6.10.15. | 0.0.0 - 6.6.10.156.7.0.0 - 6.7.8.1 | High |
CVE-2025-32378 shopware/core is vulnerable to Improper Control of Interaction Frequency in versions 6.6.0.0-rc1 - 6.6.10.3, 6.7.0.0-rc1 - 6.7.0.0-rc2 and 0.0.0 - 6.5.8.17. | 0.0.0 - 6.5.8.176.6.0.0-rc1 - 6.6.10.36.7.0.0-rc1 - 6.7.0.0-rc2 | Medium |
CVE-2025-30150 shopware/core is vulnerable to Observable Response Discrepancy in versions 6.7.0.0-rc1 - 6.7.0.0-rc1, 6.6.0.0 - 6.6.10.2 and 0.0.0 - 6.5.8.17. | 0.0.0 - 6.5.8.176.6.0.0 - 6.6.10.26.7.0.0-rc1 - 6.7.0.0-rc1 | Medium |
CVE-2025-30151 shopware/core is vulnerable to Improper Input Validation in versions 6.6.0.0 - 6.6.10.3, 6.7.0.0-rc1 - 6.7.0.0-rc2 and 0.0.0 - 6.5.8.17. | 0.0.0 - 6.5.8.176.6.0.0 - 6.6.10.36.7.0.0-rc1 - 6.7.0.0-rc2 | High |
CVE-2025-27892 shopware/core is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 6.7.0.0-rc1 - 6.7.0.0-rc1, 6.6.0.0 - 6.6.10.2 and 0.0.0 - 6.5.8.18. | 0.0.0 - 6.5.8.186.6.0.0 - 6.6.10.26.7.0.0-rc1 - 6.7.0.0-rc1 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.0 | — | — |
psr/cache Version ^3.0.0 | — | — |
twig/twig Version ^3.21.1 | — | — |
nyholm/psr7 Version ^1.5 | — | — |
ramsey/uuid Version ^4.7 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant