Title |
Severity |
Exploit |
Date |
Affected Version |
Internal hidden fields are visible on to many associations in admin api
|
Medium
|
|
Jun 28, 2021
|
< 6.4.1.1
|
Private files publicly accessible with Cloud Storage providers
|
High
|
|
Jun 28, 2021
|
< 6.4.1.1
|
Creation of order credits was not validated by acl in admin orders
|
Low
|
|
Jun 28, 2021
|
< 6.4.1.1
|
Canceling of orders not related to the logged-in user
|
Medium
|
|
Jun 28, 2021
|
< 6.4.1.1
|
CVE-2021-32716
|
Low
|
|
Jun 24, 2021
|
< 6.4.1.1
|
CVE-2021-32717
|
High
|
|
Jun 24, 2021
|
< 6.4.1.1
|
CVE-2021-32710
|
High
|
|
Jun 24, 2021
|
< 6.3.5.2
|
CVE-2021-32711
|
High
|
|
Jun 24, 2021
|
< 6.3.5.1
|
CVE-2021-32709
|
Low
|
|
Jun 24, 2021
|
< 6.4.1.1
|
After order payment process manipulation in shopware/platform and shopware/core
|
Critical
|
|
Apr 13, 2021
|
< 6.3.5.3
|