Vulnerabilities > Shopware > Shopware > 6.4.12.0

DATE CVE VULNERABILITY TITLE RISK
2024-08-08 CVE-2024-42354 Unspecified vulnerability in Shopware
Shopware is an open commerce platform.
network
high complexity
shopware
5.9
2024-08-08 CVE-2024-42355 Code Injection vulnerability in Shopware
Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag.
network
low complexity
shopware CWE-94
critical
9.8
2024-08-08 CVE-2024-42356 Code Injection vulnerability in Shopware
Shopware is an open commerce platform.
network
low complexity
shopware CWE-94
7.2
2024-08-08 CVE-2024-42357 SQL Injection vulnerability in Shopware
Shopware is an open commerce platform.
network
low complexity
shopware CWE-89
critical
9.8
2024-01-16 CVE-2024-22406 Unspecified vulnerability in Shopware
Shopware is an open headless commerce platform.
network
low complexity
shopware
critical
9.8
2024-01-16 CVE-2024-22407 Unspecified vulnerability in Shopware
Shopware is an open headless commerce platform.
network
low complexity
shopware
6.5
2024-01-16 CVE-2024-22408 Unspecified vulnerability in Shopware
Shopware is an open headless commerce platform.
network
low complexity
shopware
8.1
2023-04-17 CVE-2023-2017 Code Injection vulnerability in Shopware
Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the validation checks in `Shopware\Core\Framework\Adapter\Twig\SecurityExtension` and call any arbitrary PHP function and thus execute arbitrary code/commands via usage of fully-qualified names, supplied as array of strings, when referencing callables.
network
low complexity
shopware CWE-94
8.8
2023-01-17 CVE-2023-22730 Unspecified vulnerability in Shopware
Shopware is an open source commerce platform based on Symfony Framework and Vue js.
network
low complexity
shopware
7.5
2023-01-17 CVE-2023-22731 Unspecified vulnerability in Shopware
Shopware is an open source commerce platform based on Symfony Framework and Vue js.
network
low complexity
shopware
8.8