Vulnerabilities > Shopware > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-06-13 | CVE-2019-12799 | Deserialization of Untrusted Data vulnerability in Shopware In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. | 8.8 |
2019-01-15 | CVE-2018-20713 | SQL Injection vulnerability in Shopware Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404. | 8.8 |