shopware/core Security Advisories for 6.4.6.1 (13)
-
[MEDIUM] Broken Access Control order API in Shopware
PKSA-mm7q-gnjj-tttn CVE-2024-22407 GHSA-3867-jc5c-66qf
Affected version: <=6.5.7.3
Reported by:
GitHub -
[CRITICAL] Blind SQL injection in shopware
PKSA-ktmn-6519-qrdp CVE-2024-22406 GHSA-qmp9-2xwj-m6m9
Affected version: <=6.5.7.3
Reported by:
GitHub -
[HIGH] Improper Control of Generation of Code in Twig rendered views
PKSA-kd1k-vbw9-69fx CVE-2023-2017 GHSA-7v2v-9rm4-7m8f
Affected version: <=6.4.20.0
Reported by:
GitHub -
[MEDIUM] Shopware has Improper Input Validation issue in newsletter subscription
PKSA-zbt5-mjsz-9f2t CVE-2023-22734 GHSA-46h7-vj7x-fxg2
Affected version: <=6.4.18.0
Reported by:
GitHub -
[LOW] Shopware has Insufficient Session Expiration in Administration
PKSA-bnh5-5drc-b8g8 CVE-2023-22732 GHSA-59qg-93jg-236f
Affected version: <=6.4.18.0
Reported by:
GitHub -
[LOW] Shopware's log module vulnerable to Improper Output Neutralization
PKSA-88mf-d614-87c1 CVE-2023-22733 GHSA-7cp7-jfp6-jh4f
Affected version: <=6.4.18.0
Reported by:
GitHub -
[CRITICAL] Shopware vulnerable to Improper Control of Generation of Code in Twig rendered views
PKSA-s94v-mcmm-ycmg CVE-2023-22731 GHSA-93cw-f5jj-x85w
Affected version: <=6.4.18.0
Reported by:
GitHub -
[MEDIUM] Shopware vulnerable to Improper Input Validation of Clearance sale in cart
PKSA-zr2k-54cr-tb84 CVE-2023-22730 GHSA-8r6h-m72v-38fg
Affected version: <=6.4.18.0
Reported by:
GitHub -
[HIGH] Server-Side Request Forgery (SSRF) in Shopware
PKSA-34sw-dmrz-s3ct CVE-2022-24871 GHSA-7gm7-8q8v-9gf2
Affected version: <=6.4.9.0
Reported by:
GitHub -
[MEDIUM] Incorrect Authentication in shopware
PKSA-3mg1-qgkz-fhzr CVE-2022-24748 GHSA-83vp-6jqg-6cmr
Affected version: <=6.4.8.1
Reported by:
GitHub -
[MEDIUM] HTTP caching is marking private HTTP headers as public in Shopware
PKSA-ccnj-bqfc-887j CVE-2022-24747 GHSA-6wrh-279j-6hvw
Affected version: <=6.4.8.1
Reported by:
GitHub -
[MEDIUM] HTML injection possibility in voucher code form in Shopware
PKSA-tnyf-cn12-jhmf CVE-2022-24746 GHSA-952p-fqcp-g8pc
Affected version: <=6.4.8.0
Reported by:
GitHub -
[LOW] Shopware user session is not logged out if the password is reset via password recovery
PKSA-9h2g-h8jc-v38b CVE-2022-24744 GHSA-w267-m9c4-8555
Affected version: <=6.4.8.0
Reported by:
GitHub