Vulnerabilities > Shopware > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-04-20 | CVE-2022-24872 | Incorrect Permission Assignment for Critical Resource vulnerability in Shopware Shopware is an open commerce platform based on Symfony Framework and Vue. | 5.5 |
2022-04-20 | CVE-2022-24871 | Server-Side Request Forgery (SSRF) vulnerability in Shopware Shopware is an open commerce platform based on Symfony Framework and Vue. | 5.5 |
2022-03-29 | CVE-2022-24956 | SQL Injection vulnerability in Shopware B2B Suite An issue was discovered in Shopware B2B-Suite through 4.4.1. | 4.0 |
2022-03-09 | CVE-2022-24745 | Session Fixation vulnerability in Shopware Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. | 5.8 |
2022-03-09 | CVE-2022-24746 | Cross-site Scripting vulnerability in Shopware Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. | 4.3 |
2022-03-09 | CVE-2022-24747 | Exposure of Resource to Wrong Sphere vulnerability in Shopware Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. | 5.3 |
2022-01-05 | CVE-2022-21651 | Open Redirect vulnerability in Shopware Shopware is an open source e-commerce software platform. | 5.8 |
2022-01-05 | CVE-2022-21652 | Insufficient Session Expiration vulnerability in Shopware Shopware is an open source e-commerce software platform. | 5.5 |
2021-08-16 | CVE-2021-37711 | Server-Side Request Forgery (SSRF) vulnerability in Shopware Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. | 6.5 |
2021-08-16 | CVE-2021-37709 | Authorization Bypass Through User-Controlled Key vulnerability in Shopware Shopware is an open source eCommerce platform. | 4.0 |