Shopware is a modestly represented e-commerce platform vendor whose vulnerability footprint concentrates in its core product suite and extensions such as the B2B platform and payment integrations, serving a prominent position in the online retail software landscape. Vulnerabilities affecting the vendor skew toward moderate-to-serious outcomes, with a meaningful share reaching critical severity and a moderate tendency toward public exploit availability; the exposure recurs through application-layer weakness classes including cross-site scripting, SQL injection, improper input validation, code injection, and sensitive data exposure that are characteristic of web-facing merchant platforms. These classes reflect the vendor's role as a target for both direct attack and supply-chain compromise, since vulnerabilities in widely deployed e-commerce software can affect transaction integrity, customer data, and payment processing across many merchant instances. Defenders running Shopware should treat plugin and extension updates as critical controls, given the breadth of third-party code integration in typical deployments, and prioritize internet-exposed administrative interfaces. Live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shopware over time
Signals from CVEs in this vendor scope (69 CVEs).
69 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12799HIGH In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserial | Jun 13, 2019 | 8.8 | 68 | NO | YES |
CVE-2017-18357MEDIUM Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, wi | Jan 15, 2019 | 6.5 | 57 | NO | YES |
CVE-2016-3109CRITICAL The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code. | Apr 21, 2017 | 9.8 | 46 | NO | NO |
CVE-2025-27892MEDIUM Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024- | Apr 15, 2025 | 6.8 | 38 | NO | YES |
CVE-2017-15374MEDIUM Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remote attackers are able to inject | Oct 16, 2017 | 6.1 | 32 | NO | YES |
CVE-2024-22406CRITICAL Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their S | Jan 16, 2024 | 9.8 | 31 | NO | NO |
CVE-2019-12935MEDIUM Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI. | Jun 23, 2019 | 6.1 | 31 | NO | YES |
CVE-2023-22732CRITICAL Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker has stolen the sessi | Jan 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-37708CRITICAL Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As work | Aug 16, 2021 | 9.8 | 30 | NO | NO |
CVE-2023-2017HIGH Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows rem | Apr 17, 2023 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (69 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shopware.
Media articles that mention a CVE ID that affects a product developed by Shopware — matched by CVE ID, not by vendor name.