Technology · Packagist
shopware/shopware (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 32 vulnerabilities in shopware/shopware (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-23498, was published on 14 January 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About shopware/shopware (Packagist)
An open-source e-commerce platform based on Symfony and Vue.js.
Latest shopware/shopware (Packagist) vulnerabilities
- CVE-2026-23498: Shopware Has Improper Control of Generation of Code in Twig rendered viewslowCVSS 3.1EPSS 0.4%
- Shopware: Reflective Cross Site-Scripting (XSS) in CMS componentslowCVSS 3.1
- Shopware Remote Code Execution VulnerabilitylowCVSS 3.1
- Shopware Remote Code Execution VulnerabilitylowCVSS 3.1
- Shopware Non-Persistent XSS in the FrontendlowCVSS 3.1
- CVE-2023-34099: Shopware improper mail validation vulnerabilitylowCVSS 3.1EPSS 0.7%
- CVE-2023-34098: Shopware dependency configuration exposedlowCVSS 3.1EPSS 0.6%
- CVE-2022-48150: Shopware vulnerable to cross-site scripting (XSS)lowCVSS 3.1EPSS 0.6%
- CVE-2022-36101: Shopware contains sensitive data in backend customer modulelowCVSS 3.1EPSS 0.7%
- CVE-2022-36102: Shopware access control list bypassed via crafted specific URLslowCVSS 3.1EPSS 0.8%
- CVE-2022-31148: Shopware vulnerable to persistent cross site scripting (XSS) in customer modulelowCVSS 3.1EPSS 0.7%
- CVE-2022-31057: Authenticated Stored Cross-site Scripting in ShopwarelowCVSS 3.1EPSS 0.7%
- CVE-2019-12935: Shopware Cross-site Scripting VulnerabilitylowCVSS 3EPSS 2.7%
- CVE-2019-12799: Shopware Insecure Deserialization VulnerabilitylowCVSS 3EPSS 54.7%
- CVE-2017-15374: Shopware XSS VulnerabilitylowCVSS 3EPSS 4.8%
- CVE-2018-20713: Shopware SQL InjectionlowCVSS 3EPSS 1.1%
- CVE-2017-18357: Shopware XXE VulnerabilitylowCVSS 3EPSS 27.1%
- CVE-2022-24892: Multiple valid tokens for password reset in ShopwarelowCVSS 3.1EPSS 0.9%
- CVE-2022-24879: Malfunction of CSRF token validation in ShopwarelowCVSS 3.1EPSS 0.6%
- CVE-2022-24873: Reflected Cross-site Scripting in Shopware storefrontlowCVSS 3.1EPSS 0.8%
- CVE-2022-21651: Open redirect in shopwarelowCVSS 3.1EPSS 0.8%
- CVE-2022-21652: Insufficient Session Expiration in shopwarelowCVSS 3.1EPSS 0.8%
- CVE-2021-41188: Authenticated Stored XSS in shopware/shopwarelowCVSS 3.1EPSS 0.8%
- CVE-2021-32713: Cross-site scriptinglowCVSS 3.1EPSS 0.7%
- CVE-2021-32712: Exposure of Sensitive Information to an Unauthorized ActorlowCVSS 3.1EPSS 1.1%
Most severe shopware/shopware (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- Shopware sensitive file exposure via incorrect web root configurationmediumCVSS 5.3
- CVE-2021-32712: Exposure of Sensitive Information to an Unauthorized ActorlowCVSS 3.1EPSS 1.1%
- CVE-2022-24892: Multiple valid tokens for password reset in ShopwarelowCVSS 3.1EPSS 0.9%
- CVE-2022-24873: Reflected Cross-site Scripting in Shopware storefrontlowCVSS 3.1EPSS 0.8%
- CVE-2022-21652: Insufficient Session Expiration in shopwarelowCVSS 3.1EPSS 0.8%
- CVE-2022-36102: Shopware access control list bypassed via crafted specific URLslowCVSS 3.1EPSS 0.8%
- CVE-2022-21651: Open redirect in shopwarelowCVSS 3.1EPSS 0.8%
- CVE-2021-41188: Authenticated Stored XSS in shopware/shopwarelowCVSS 3.1EPSS 0.8%
- CVE-2021-32713: Cross-site scriptinglowCVSS 3.1EPSS 0.7%
- CVE-2022-36101: Shopware contains sensitive data in backend customer modulelowCVSS 3.1EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/shopware-shopware.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "shopware/shopware (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/shopware-shopware, 27 September 2026.