Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Shopware

First CVE: Apr 21, 2017Active for: 9 yearsTotal CVEs: 69
49.6
VTI Score
High

Shopware is a modestly represented e-commerce platform vendor whose vulnerability footprint concentrates in its core product suite and extensions such as the B2B platform and payment integrations, serving a prominent position in the online retail software landscape. Vulnerabilities affecting the vendor skew toward moderate-to-serious outcomes, with a meaningful share reaching critical severity and a moderate tendency toward public exploit availability; the exposure recurs through application-layer weakness classes including cross-site scripting, SQL injection, improper input validation, code injection, and sensitive data exposure that are characteristic of web-facing merchant platforms. These classes reflect the vendor's role as a target for both direct attack and supply-chain compromise, since vulnerabilities in widely deployed e-commerce software can affect transaction integrity, customer data, and payment processing across many merchant instances. Defenders running Shopware should treat plugin and extension updates as critical controls, given the breadth of third-party code integration in typical deployments, and prioritize internet-exposed administrative interfaces. Live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
69
Total CVEs
More Total CVEs than 99% of tracked vendors
2.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Shopware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 21, 2017
9 years ago
Most Recent CVE
Mar 11, 2026
135 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (69 CVEs).

69 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-12799HIGH
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserial
Jun 13, 20198.868NOYES
CVE-2017-18357MEDIUM
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, wi
Jan 15, 20196.557NOYES
CVE-2016-3109CRITICAL
The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
Apr 21, 20179.846NONO
CVE-2025-27892MEDIUM
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-
Apr 15, 20256.838NOYES
CVE-2017-15374MEDIUM
Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remote attackers are able to inject
Oct 16, 20176.132NOYES
CVE-2024-22406CRITICAL
Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their S
Jan 16, 20249.831NONO
CVE-2019-12935MEDIUM
Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
Jun 23, 20196.131NOYES
CVE-2023-22732CRITICAL
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker has stolen the sessi
Jan 17, 20239.830NONO
CVE-2021-37708CRITICAL
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As work
Aug 16, 20219.830NONO
CVE-2023-2017HIGH
Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows rem
Apr 17, 20238.829NONO
View all 69 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products69 CVEs
49%
41%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network69 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low64 (92.8%)
High5 (7.2%)
Unknown0 (0.0%)
User Interaction
None52 (75.4%)
Unknown0 (0.0%)
Required17 (24.6%)
Privileges Required
Low22 (31.9%)
High7 (10.1%)
None40 (58.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (69 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
2.9% of CVEs· 98th percentile
Nuclei
2 CVEs
2.9% of CVEs· 95th percentile
ExploitDB
2 CVEs
2.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Shopware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Shopware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Shopware's Products

View all 5 CNAs →

Top CWEs