CVE-2025-27892 is a SQL injection vulnerability affecting Shopware versions prior to 6.5.8.13, specifically within the /api/search/order endpoint. This medium-severity vulnerability (CVSS 6.8) is a regression of previously patched issues, allowing an authenticated attacker to execute arbitrary SQL queries with high impact on confidentiality and moderate impact on integrity and availability. While not currently observed in active exploitation, public exploit templates for Nuclei exist, indicating a readily available method for exploitation. Community discussion and media coverage are minimal at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.5.8.17CPE matchmatch criteria | cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:* | ||
>= 6.6.0.0, < 6.6.10.3CPE matchmatch criteria | cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:* | ||
6.7.0.0CPE matchmatch criteria | cpe:2.3:a:shopware:shopware:6.7.0.0:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.