| CVE |
Severity |
CVSS |
Risk |
Published |
Description |
Impact |
| CVE-2025-67648 |
unknown |
— |
— |
6mo ago |
Shopware Storefront Reflected XSS in Storefront Login Page |
|
| CVE-2024-27917 |
unknown |
— |
— |
2y ago |
Shopware's session is persistent in Cache for 404 pages |
|
| CVE-2022-24747 |
unknown |
— |
— |
4y ago |
HTTP caching is marking private HTTP headers as public in Shopware |
|
| CVE-2022-24746 |
unknown |
— |
— |
4y ago |
HTML injection possibility in voucher code form in Shopware |
|
| CVE-2022-24745 |
unknown |
— |
— |
4y ago |
Shopware guest session is shared between customers |
|