Vulnerabilities > Shopware > High

DATE CVE VULNERABILITY TITLE RISK
2019-06-13 CVE-2019-12799 Deserialization of Untrusted Data vulnerability in Shopware
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated.
network
low complexity
shopware CWE-502
8.8
2019-01-15 CVE-2018-20713 SQL Injection vulnerability in Shopware
Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.
network
low complexity
shopware CWE-89
8.8