Vulnerabilities > Shopware > Shopware > 5.2.7

DATE CVE VULNERABILITY TITLE RISK
2021-06-24 CVE-2021-32712 Information Exposure Through an Error Message vulnerability in Shopware
Shopware is an open source eCommerce platform.
network
low complexity
shopware CWE-209
5.3
2021-06-24 CVE-2021-32713 Unspecified vulnerability in Shopware
Shopware is an open source eCommerce platform.
network
low complexity
shopware
4.8
2021-06-24 CVE-2021-32710 Unspecified vulnerability in Shopware
Shopware is an open source eCommerce platform.
network
low complexity
shopware
7.5
2021-06-24 CVE-2021-32711 Unspecified vulnerability in Shopware
Shopware is an open source eCommerce platform.
network
low complexity
shopware
7.5
2021-06-24 CVE-2021-32709 Unspecified vulnerability in Shopware
Shopware is an open source eCommerce platform.
network
low complexity
shopware
4.9
2020-07-28 CVE-2020-13997 Information Exposure Through an Error Message vulnerability in Shopware
In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.
network
low complexity
shopware CWE-209
7.5
2020-07-28 CVE-2020-13971 Cross-site Scripting vulnerability in Shopware
In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript.
network
low complexity
shopware CWE-79
5.4
2020-07-28 CVE-2020-13970 Server-Side Request Forgery (SSRF) vulnerability in Shopware
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature.
network
low complexity
shopware CWE-918
8.8
2019-06-23 CVE-2019-12935 Cross-site Scripting vulnerability in Shopware
Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
network
low complexity
shopware CWE-79
6.1
2019-06-13 CVE-2019-12799 Deserialization of Untrusted Data vulnerability in Shopware
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated.
network
low complexity
shopware CWE-502
8.8