| Title |
Severity |
Exploit |
Date |
Affected Version |
|
Shopware Customer Orders can be canceled, even if refunds are disabled
|
Medium
|
|
Oct 21, 2025
|
>= 6.7.0.0 < 6.7.3.1
< 6.6.10.7
|
|
Shopware exposes sensitive user information via CSV export mapping
|
Medium
|
|
Oct 21, 2025
|
>= 6.7.0.0 < 6.7.3.1
< 6.6.10.7
|
|
Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice
|
Low
|
|
Oct 21, 2025
|
>= 6.7.0.0 < 6.7.3.1
< 6.6.10.7
|
|
Shopware vulnerable to path traversal via Plugin upload
|
Low
|
|
Oct 21, 2025
|
>= 6.7.0.0 < 6.7.3.1
< 6.6.10.7
|
|
Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually
|
Medium
|
|
Oct 21, 2025
|
>= 6.7.0.0 < 6.7.3.1
< 6.6.10.7
|
|
CVE-2025-7954
|
Medium
|
|
Aug 6, 2025
|
<= 6.6.10.4
|
|
CVE-2025-32378
|
Low
|
|
Apr 9, 2025
|
>= 6.6.0.0-rc1 < 6.6.10.3
>= 6.7.0.0-rc1 < 6.7.0.0-rc2
< 6.5.8.17
|
|
Shopware Broken ACL on Document retrieval to access other customers documents
|
Medium
|
|
Apr 8, 2025
|
>= 6.6.0.0 < 6.6.10.3
>= 6.7.0.0-rc1 < 6.7.0.0-rc2
< 6.5.8.17
|
|
CVE-2025-27892
|
High
|
|
Apr 8, 2025
|
>= 6.6.0.0 < 6.6.10.3
>= 6.7.0.0-rc1 < 6.7.0.0-rc2
== 6.7.0.0-rc1
< 6.5.8.18
|
|
CVE-2025-30151
|
High
|
|
Apr 8, 2025
|
>= 6.6.0.0 < 6.6.10.3
>= 6.7.0.0-rc1 < 6.7.0.0-rc2
< 6.5.8.17
|