Junglewise Threat Intelligence

Shopware: Reflective Cross Site-Scripting (XSS) in CMS components

Severity: low · CVSS 3.1 · Published 2025-09-10

Technologies: shopware/core (Packagist), shopware/shopware (Packagist). Vendors: Packagist.

Executive brief

Shopware: Reflective Cross Site-Scripting (XSS) in CMS components

Affected products

  • Packagist shopware/core
  • Packagist shopware/shopware

Related threats