Vulnerability Database

With exploit

shopware / platform

Title Severity Exploit Date Affected Version
CVE-2021-32709 Low Jun 24, 2021 < 6.4.1.1
After order payment process manipulation in shopware/platform and shopware/core Critical Apr 13, 2021 < 6.3.5.3
Leak of information via Store-API aggregations in shopware/platform and shopware/core Critical Apr 13, 2021 < 6.3.5.3
Authenticated remote code execution Medium Mar 12, 2021 < 6.3.5.2
Potential Session Hijacking Low Mar 12, 2021 < 6.3.5.2
Leak of information via Store-API Critical Feb 10, 2021 < 6.3.5.1
Generation of fake documents via public GET-call Low Feb 10, 2021 < 6.3.5.1
Authenticated Server Side Request Forgery Low Dec 21, 2020 < 6.3.4.1
Information exposure via query strings in URL Low Dec 21, 2020 < 6.3.4.1
Authenticated Privilege Escalation Low Dec 21, 2020 < 6.3.4.1