| Title |
Severity |
Exploit |
Date |
Affected Version |
|
CVE-2022-24744
|
Low
|
|
Mar 10, 2022
|
< 6.4.8.1
|
|
Webcache Poisoning in shopware/platform and shopware/core
|
Critical
|
|
Nov 24, 2021
|
< 6.4.6.1
|
|
CVE-2021-37710
|
Medium
|
|
Aug 17, 2021
|
< 6.4.3.1
|
|
CVE-2021-37711
|
High
|
|
Aug 17, 2021
|
< 6.4.3.1
|
|
CVE-2021-37709
|
Medium
|
|
Aug 17, 2021
|
< 6.4.3.1
|
|
CVE-2021-37708
|
Critical
|
|
Aug 16, 2021
|
< 6.4.3.1
|
|
CVE-2021-37707
|
High
|
|
Aug 16, 2021
|
< 6.4.3.1
|
|
non-admin users can create integration role with administrator role
|
Medium
|
|
Jun 28, 2021
|
< 6.4.1.1
|
|
Internal hidden fields are visible on to many associations in admin api
|
Medium
|
|
Jun 28, 2021
|
< 6.4.1.1
|
|
Private files publicly accessible with Cloud Storage providers
|
High
|
|
Jun 28, 2021
|
< 6.4.1.1
|