{"schema_version":1,"title":"shopware/core (Packagist) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 39 vulnerabilities in shopware/core (Packagist): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-48013, was published on 23 July 2026.","url":"https://junglewise.ai/threats/technologies/shopware-core","json_url":"https://junglewise.ai/threats/technologies/shopware-core.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/shopware-core","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":39,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":3},"latest":[{"cve":"CVE-2026-48013","cvss":4.1,"epss":0.0037,"slug":"cve-2026-48013-shopware-ssrf-in-media-external-link-endpoint","title":"Shopware SSRF in Media External-Link endpoint","severity":"medium","exploited":false,"published_at":"2026-07-23T20:17:08.92+00:00","url":"https://junglewise.ai/threats/cve-2026-48013-shopware-ssrf-in-media-external-link-endpoint"},{"cve":"CVE-2026-48012","cvss":4.3,"epss":0.0028,"slug":"cve-2026-48012-shopware-open-redirect-in-sso-entry-point-via-referer-header","title":"Shopware open redirect in SSO entry point via Referer header","severity":"medium","exploited":false,"published_at":"2026-07-23T20:17:08.777+00:00","url":"https://junglewise.ai/threats/cve-2026-48012-shopware-open-redirect-in-sso-entry-point-via-referer-header"},{"cve":"CVE-2026-23498","cvss":3.1,"epss":0.0045,"slug":"cve-2026-23498-shopware-has-improper-control-of-generation-of-code-in-twig","title":"Shopware Has Improper Control of Generation of Code in Twig rendered views","severity":"low","exploited":false,"published_at":"2026-01-14T16:54:27+00:00","url":"https://junglewise.ai/threats/cve-2026-23498-shopware-has-improper-control-of-generation-of-code-in-twig"},{"cvss":3.1,"slug":"shopware-reflective-cross-site-scripting-xss-in-cms-components-a33d7f04","title":"Shopware: Reflective Cross Site-Scripting (XSS) in CMS components","severity":"low","exploited":false,"published_at":"2025-09-10T20:46:20+00:00","url":"https://junglewise.ai/threats/shopware-reflective-cross-site-scripting-xss-in-cms-components-a33d7f04"},{"cve":"CVE-2024-22407","cvss":3.1,"epss":0.004,"slug":"cve-2024-22407-broken-access-control-order-api-in-shopware","title":"Broken Access Control order API in Shopware","severity":"low","exploited":false,"published_at":"2024-01-17T20:29:33+00:00","url":"https://junglewise.ai/threats/cve-2024-22407-broken-access-control-order-api-in-shopware"},{"cve":"CVE-2024-22406","cvss":3.1,"epss":0.0064,"slug":"cve-2024-22406-blind-sql-injection-in-shopware","title":"Blind SQL injection in shopware","severity":"low","exploited":false,"published_at":"2024-01-17T20:28:50+00:00","url":"https://junglewise.ai/threats/cve-2024-22406-blind-sql-injection-in-shopware"},{"cve":"CVE-2023-2017","cvss":3.1,"epss":0.0207,"slug":"cve-2023-2017-shopware-has-improper-control-of-generation-of-code-in-twig","title":"Shopware Has Improper Control of Generation of Code in Twig rendered views","severity":"low","exploited":false,"published_at":"2023-04-18T13:14:20+00:00","url":"https://junglewise.ai/threats/cve-2023-2017-shopware-has-improper-control-of-generation-of-code-in-twig"},{"cve":"CVE-2023-22734","cvss":3.1,"epss":0.006,"slug":"cve-2023-22734-shopware-has-improper-input-validation-issue-in-newsletter","title":"Shopware has Improper Input Validation issue in newsletter subscription","severity":"low","exploited":false,"published_at":"2023-01-20T23:18:41+00:00","url":"https://junglewise.ai/threats/cve-2023-22734-shopware-has-improper-input-validation-issue-in-newsletter"},{"cve":"CVE-2023-22732","cvss":3.1,"epss":0.0073,"slug":"cve-2023-22732-shopware-has-insufficient-session-expiration-in-administration","title":"Shopware has Insufficient Session Expiration in Administration","severity":"low","exploited":false,"published_at":"2023-01-20T23:18:17+00:00","url":"https://junglewise.ai/threats/cve-2023-22732-shopware-has-insufficient-session-expiration-in-administration"},{"cve":"CVE-2023-22733","cvss":3.1,"epss":0.0071,"slug":"cve-2023-22733-shopware-s-log-module-vulnerable-to-improper-output","title":"Shopware's log module vulnerable to Improper Output Neutralization","severity":"low","exploited":false,"published_at":"2023-01-20T17:33:54+00:00","url":"https://junglewise.ai/threats/cve-2023-22733-shopware-s-log-module-vulnerable-to-improper-output"},{"cve":"CVE-2023-22731","cvss":3.1,"epss":0.0133,"slug":"cve-2023-22731-shopware-vulnerable-to-improper-control-of-generation-of-code-in","title":"Shopware vulnerable to Improper Control of Generation of Code in Twig rendered views","severity":"low","exploited":false,"published_at":"2023-01-17T23:58:06+00:00","url":"https://junglewise.ai/threats/cve-2023-22731-shopware-vulnerable-to-improper-control-of-generation-of-code-in"},{"cve":"CVE-2023-22730","cvss":3.1,"epss":0.0066,"slug":"cve-2023-22730-shopware-vulnerable-to-improper-input-validation-of-clearance","title":"Shopware vulnerable to Improper Input Validation of Clearance sale in cart","severity":"low","exploited":false,"published_at":"2023-01-17T23:57:23+00:00","url":"https://junglewise.ai/threats/cve-2023-22730-shopware-vulnerable-to-improper-input-validation-of-clearance"},{"cve":"CVE-2020-13997","cvss":3.1,"epss":0.0149,"slug":"cve-2020-13997-shopware-database-password-is-leaked-to-an-unauthenticated-users","title":"Shopware database password is leaked to an unauthenticated users","severity":"low","exploited":false,"published_at":"2022-05-24T17:24:28+00:00","url":"https://junglewise.ai/threats/cve-2020-13997-shopware-database-password-is-leaked-to-an-unauthenticated-users"},{"cve":"CVE-2022-24872","cvss":3.1,"epss":0.0105,"slug":"cve-2022-24872-improper-access-control-in-shopware","title":"Improper Access Control in Shopware","severity":"low","exploited":false,"published_at":"2022-04-22T21:04:27+00:00","url":"https://junglewise.ai/threats/cve-2022-24872-improper-access-control-in-shopware"},{"cve":"CVE-2022-24871","cvss":3.1,"epss":0.0106,"slug":"cve-2022-24871-server-side-request-forgery-ssrf-in-shopware","title":"Server-Side Request Forgery (SSRF) in Shopware","severity":"low","exploited":false,"published_at":"2022-04-22T21:04:07+00:00","url":"https://junglewise.ai/threats/cve-2022-24871-server-side-request-forgery-ssrf-in-shopware"},{"cve":"CVE-2022-24748","cvss":3.1,"epss":0.0076,"slug":"cve-2022-24748-incorrect-authentication-in-shopware","title":"Incorrect Authentication in shopware","severity":"low","exploited":false,"published_at":"2022-03-10T18:02:14+00:00","url":"https://junglewise.ai/threats/cve-2022-24748-incorrect-authentication-in-shopware"},{"cve":"CVE-2022-24747","cvss":3.1,"epss":0.011,"slug":"cve-2022-24747-http-caching-is-marking-private-http-headers-as-public-in","title":"HTTP caching is marking private HTTP headers as public in Shopware","severity":"low","exploited":false,"published_at":"2022-03-10T17:55:21+00:00","url":"https://junglewise.ai/threats/cve-2022-24747-http-caching-is-marking-private-http-headers-as-public-in"},{"cve":"CVE-2022-24746","cvss":3.1,"epss":0.0084,"slug":"cve-2022-24746-html-injection-possibility-in-voucher-code-form-in-shopware","title":"HTML injection possibility in voucher code form in Shopware","severity":"low","exploited":false,"published_at":"2022-03-10T17:49:26+00:00","url":"https://junglewise.ai/threats/cve-2022-24746-html-injection-possibility-in-voucher-code-form-in-shopware"},{"cve":"CVE-2022-24744","cvss":3.1,"epss":0.0049,"slug":"cve-2022-24744-shopware-user-session-is-not-logged-out-if-the-password-is-reset","title":"Shopware user session is not logged out if the password is reset via password recovery","severity":"low","exploited":false,"published_at":"2022-03-10T17:37:43+00:00","url":"https://junglewise.ai/threats/cve-2022-24744-shopware-user-session-is-not-logged-out-if-the-password-is-reset"},{"slug":"webcache-poisoning-in-shopware-platform-and-shopware-core-640c3fe5","title":"Webcache Poisoning in shopware/platform and shopware/core","severity":"info","exploited":false,"published_at":"2021-11-24T20:05:19+00:00","url":"https://junglewise.ai/threats/webcache-poisoning-in-shopware-platform-and-shopware-core-640c3fe5"},{"cve":"CVE-2021-37709","cvss":3.1,"epss":0.0077,"slug":"cve-2021-37709-insecure-direct-object-reference-of-log-files-of-the-import","title":"Insecure direct object reference of log files of the Import/Export feature","severity":"low","exploited":false,"published_at":"2021-08-30T16:14:19+00:00","url":"https://junglewise.ai/threats/cve-2021-37709-insecure-direct-object-reference-of-log-files-of-the-import"},{"cve":"CVE-2021-37708","cvss":3.1,"epss":0.0236,"slug":"cve-2021-37708-command-injection-in-mail-agent-settings","title":"Command injection in mail agent settings","severity":"low","exploited":false,"published_at":"2021-08-30T16:14:09+00:00","url":"https://junglewise.ai/threats/cve-2021-37708-command-injection-in-mail-agent-settings"},{"cve":"CVE-2021-37707","cvss":3.1,"epss":0.0089,"slug":"cve-2021-37707-manipulation-of-product-reviews-via-api","title":"Manipulation of product reviews via API","severity":"low","exploited":false,"published_at":"2021-08-30T16:14:00+00:00","url":"https://junglewise.ai/threats/cve-2021-37707-manipulation-of-product-reviews-via-api"},{"cve":"CVE-2021-37710","cvss":3.1,"epss":0.0074,"slug":"cve-2021-37710-cross-site-scripting-via-svg-media-files","title":"Cross-Site Scripting via SVG media files","severity":"low","exploited":false,"published_at":"2021-08-23T19:43:00+00:00","url":"https://junglewise.ai/threats/cve-2021-37710-cross-site-scripting-via-svg-media-files"},{"cve":"CVE-2021-37711","cvss":3.1,"epss":0.0106,"slug":"cve-2021-37711-authenticated-server-side-request-forgery-in-file-upload-via-url","title":"Authenticated server-side request forgery in file upload via URL.","severity":"low","exploited":false,"published_at":"2021-08-23T19:42:49+00:00","url":"https://junglewise.ai/threats/cve-2021-37711-authenticated-server-side-request-forgery-in-file-upload-via-url"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"wwbn/avideo (Packagist)","slug":"wwbn-avideo","vulnerabilities":169,"url":"https://junglewise.ai/threats/technologies/wwbn-avideo"},{"name":"getgrav/grav (Packagist)","slug":"getgrav-grav","vulnerabilities":144,"url":"https://junglewise.ai/threats/technologies/getgrav-grav"},{"name":"thorsten/phpmyfaq (Packagist)","slug":"thorsten-phpmyfaq","vulnerabilities":138,"url":"https://junglewise.ai/threats/technologies/thorsten-phpmyfaq"},{"name":"pimcore/pimcore (Packagist)","slug":"pimcore-pimcore","vulnerabilities":136,"url":"https://junglewise.ai/threats/technologies/pimcore-pimcore"},{"name":"dolibarr/dolibarr (Packagist)","slug":"dolibarr-dolibarr","vulnerabilities":125,"url":"https://junglewise.ai/threats/technologies/dolibarr-dolibarr"},{"name":"drupal/core (Packagist)","slug":"packagist-drupal-core","vulnerabilities":116,"url":"https://junglewise.ai/threats/technologies/packagist-drupal-core"},{"name":"librenms/librenms (Packagist)","slug":"librenms-librenms","vulnerabilities":113,"url":"https://junglewise.ai/threats/technologies/librenms-librenms"},{"name":"microweber/microweber (Packagist)","slug":"microweber-microweber","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/microweber-microweber"},{"name":"concrete5/concrete5 (Packagist)","slug":"concrete5-concrete5","vulnerabilities":93,"url":"https://junglewise.ai/threats/technologies/concrete5-concrete5"},{"name":"craftcms/cms (Packagist)","slug":"craftcms-cms","vulnerabilities":90,"url":"https://junglewise.ai/threats/technologies/craftcms-cms"},{"name":"snipe/snipe-it (Packagist)","slug":"snipe-snipe-it","vulnerabilities":80,"url":"https://junglewise.ai/threats/technologies/snipe-snipe-it"},{"name":"phpmyfaq/phpmyfaq (Packagist)","slug":"phpmyfaq-phpmyfaq","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/phpmyfaq-phpmyfaq"}],"technology":{"hub":true,"name":"shopware/core (Packagist)","slug":"shopware-core","vendor":{"name":"Packagist","slug":"packagist","url":"https://junglewise.ai/threats/vendors/packagist"},"aliases":[],"homepage":"https://www.shopware.com/","repo_url":"https://github.com/shopware/shopware","description":"The core logic and functionality package for the Shopware e-commerce system.","url":"https://junglewise.ai/threats/technologies/shopware-core"},"most_severe":[{"cve":"CVE-2026-48012","cvss":4.3,"epss":0.0028,"slug":"cve-2026-48012-shopware-open-redirect-in-sso-entry-point-via-referer-header","title":"Shopware open redirect in SSO entry point via Referer header","severity":"medium","exploited":false,"published_at":"2026-07-23T20:17:08.777+00:00","url":"https://junglewise.ai/threats/cve-2026-48012-shopware-open-redirect-in-sso-entry-point-via-referer-header"},{"cve":"CVE-2026-48013","cvss":4.1,"epss":0.0037,"slug":"cve-2026-48013-shopware-ssrf-in-media-external-link-endpoint","title":"Shopware SSRF in Media External-Link endpoint","severity":"medium","exploited":false,"published_at":"2026-07-23T20:17:08.92+00:00","url":"https://junglewise.ai/threats/cve-2026-48013-shopware-ssrf-in-media-external-link-endpoint"},{"cve":"CVE-2021-37708","cvss":3.1,"epss":0.0236,"slug":"cve-2021-37708-command-injection-in-mail-agent-settings","title":"Command injection in mail agent settings","severity":"low","exploited":false,"published_at":"2021-08-30T16:14:09+00:00","url":"https://junglewise.ai/threats/cve-2021-37708-command-injection-in-mail-agent-settings"},{"cve":"CVE-2023-2017","cvss":3.1,"epss":0.0207,"slug":"cve-2023-2017-shopware-has-improper-control-of-generation-of-code-in-twig","title":"Shopware Has Improper Control of Generation of Code in Twig rendered views","severity":"low","exploited":false,"published_at":"2023-04-18T13:14:20+00:00","url":"https://junglewise.ai/threats/cve-2023-2017-shopware-has-improper-control-of-generation-of-code-in-twig"},{"cve":"CVE-2020-13997","cvss":3.1,"epss":0.0149,"slug":"cve-2020-13997-shopware-database-password-is-leaked-to-an-unauthenticated-users","title":"Shopware database password is leaked to an unauthenticated users","severity":"low","exploited":false,"published_at":"2022-05-24T17:24:28+00:00","url":"https://junglewise.ai/threats/cve-2020-13997-shopware-database-password-is-leaked-to-an-unauthenticated-users"},{"cve":"CVE-2021-32717","cvss":3.1,"epss":0.0146,"slug":"cve-2021-32717-exposure-of-sensitive-information-to-an-unauthorized-actor","title":"Private files publicly accessible with Cloud Storage providers","severity":"low","exploited":false,"published_at":"2021-06-28T18:20:42+00:00","url":"https://junglewise.ai/threats/cve-2021-32717-exposure-of-sensitive-information-to-an-unauthorized-actor"},{"cve":"CVE-2023-22731","cvss":3.1,"epss":0.0133,"slug":"cve-2023-22731-shopware-vulnerable-to-improper-control-of-generation-of-code-in","title":"Shopware vulnerable to Improper Control of Generation of Code in Twig rendered views","severity":"low","exploited":false,"published_at":"2023-01-17T23:58:06+00:00","url":"https://junglewise.ai/threats/cve-2023-22731-shopware-vulnerable-to-improper-control-of-generation-of-code-in"},{"cve":"CVE-2021-32716","cvss":3.1,"epss":0.0111,"slug":"cve-2021-32716-exposure-of-sensitive-information-to-an-unauthorized-actor","title":"Internal hidden fields are visible on to many associations in admin api","severity":"low","exploited":false,"published_at":"2021-06-28T18:20:53+00:00","url":"https://junglewise.ai/threats/cve-2021-32716-exposure-of-sensitive-information-to-an-unauthorized-actor"},{"cve":"CVE-2022-24747","cvss":3.1,"epss":0.011,"slug":"cve-2022-24747-http-caching-is-marking-private-http-headers-as-public-in","title":"HTTP caching is marking private HTTP headers as public in Shopware","severity":"low","exploited":false,"published_at":"2022-03-10T17:55:21+00:00","url":"https://junglewise.ai/threats/cve-2022-24747-http-caching-is-marking-private-http-headers-as-public-in"},{"cve":"CVE-2022-24871","cvss":3.1,"epss":0.0106,"slug":"cve-2022-24871-server-side-request-forgery-ssrf-in-shopware","title":"Server-Side Request Forgery (SSRF) in Shopware","severity":"low","exploited":false,"published_at":"2022-04-22T21:04:07+00:00","url":"https://junglewise.ai/threats/cve-2022-24871-server-side-request-forgery-ssrf-in-shopware"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}