{"schema_version":1,"title":"shopware/shopware (Packagist) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 32 vulnerabilities in shopware/shopware (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-23498, was published on 14 January 2026.","url":"https://junglewise.ai/threats/technologies/shopware-shopware","json_url":"https://junglewise.ai/threats/technologies/shopware-shopware.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/shopware-shopware","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":32,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":1},"latest":[{"cve":"CVE-2026-23498","cvss":3.1,"epss":0.0045,"slug":"cve-2026-23498-shopware-has-improper-control-of-generation-of-code-in-twig","title":"Shopware Has Improper Control of Generation of Code in Twig rendered views","severity":"low","exploited":false,"published_at":"2026-01-14T16:54:27+00:00","url":"https://junglewise.ai/threats/cve-2026-23498-shopware-has-improper-control-of-generation-of-code-in-twig"},{"cvss":3.1,"slug":"shopware-reflective-cross-site-scripting-xss-in-cms-components-a33d7f04","title":"Shopware: Reflective Cross Site-Scripting (XSS) in CMS components","severity":"low","exploited":false,"published_at":"2025-09-10T20:46:20+00:00","url":"https://junglewise.ai/threats/shopware-reflective-cross-site-scripting-xss-in-cms-components-a33d7f04"},{"cvss":3.1,"slug":"shopware-remote-code-execution-vulnerability-c04cc911","title":"Shopware Remote Code Execution Vulnerability","severity":"low","exploited":false,"published_at":"2024-05-21T21:00:39+00:00","url":"https://junglewise.ai/threats/shopware-remote-code-execution-vulnerability-c04cc911"},{"cvss":3.1,"slug":"shopware-remote-code-execution-vulnerability-acc424a9","title":"Shopware Remote Code Execution Vulnerability","severity":"low","exploited":false,"published_at":"2024-05-21T20:52:57+00:00","url":"https://junglewise.ai/threats/shopware-remote-code-execution-vulnerability-acc424a9"},{"cvss":3.1,"slug":"shopware-non-persistent-xss-in-the-frontend-fbad9d6e","title":"Shopware Non-Persistent XSS in the Frontend","severity":"low","exploited":false,"published_at":"2024-05-21T20:42:46+00:00","url":"https://junglewise.ai/threats/shopware-non-persistent-xss-in-the-frontend-fbad9d6e"},{"cve":"CVE-2023-34099","cvss":3.1,"epss":0.0065,"slug":"cve-2023-34099-shopware-improper-mail-validation-vulnerability","title":"Shopware improper mail validation vulnerability","severity":"low","exploited":false,"published_at":"2023-06-28T22:34:08+00:00","url":"https://junglewise.ai/threats/cve-2023-34099-shopware-improper-mail-validation-vulnerability"},{"cve":"CVE-2023-34098","cvss":3.1,"epss":0.0061,"slug":"cve-2023-34098-shopware-dependency-configuration-exposed","title":"Shopware dependency configuration exposed","severity":"low","exploited":false,"published_at":"2023-06-28T22:33:26+00:00","url":"https://junglewise.ai/threats/cve-2023-34098-shopware-dependency-configuration-exposed"},{"cve":"CVE-2022-48150","cvss":3.1,"epss":0.0058,"slug":"cve-2022-48150-shopware-vulnerable-to-cross-site-scripting-xss","title":"Shopware vulnerable to cross-site scripting (XSS)","severity":"low","exploited":false,"published_at":"2023-04-21T15:30:18+00:00","url":"https://junglewise.ai/threats/cve-2022-48150-shopware-vulnerable-to-cross-site-scripting-xss"},{"cve":"CVE-2022-36101","cvss":3.1,"epss":0.0068,"slug":"cve-2022-36101-shopware-contains-sensitive-data-in-backend-customer-module","title":"Shopware contains sensitive data in backend customer module","severity":"low","exploited":false,"published_at":"2022-09-16T21:02:55+00:00","url":"https://junglewise.ai/threats/cve-2022-36101-shopware-contains-sensitive-data-in-backend-customer-module"},{"cve":"CVE-2022-36102","cvss":3.1,"epss":0.0078,"slug":"cve-2022-36102-shopware-access-control-list-bypassed-via-crafted-specific-urls","title":"Shopware access control list bypassed via crafted specific URLs","severity":"low","exploited":false,"published_at":"2022-09-16T21:01:29+00:00","url":"https://junglewise.ai/threats/cve-2022-36102-shopware-access-control-list-bypassed-via-crafted-specific-urls"},{"cve":"CVE-2022-31148","cvss":3.1,"epss":0.0067,"slug":"cve-2022-31148-shopware-vulnerable-to-persistent-cross-site-scripting-xss-in","title":"Shopware vulnerable to persistent cross site scripting (XSS) in customer module","severity":"low","exploited":false,"published_at":"2022-07-27T22:06:09+00:00","url":"https://junglewise.ai/threats/cve-2022-31148-shopware-vulnerable-to-persistent-cross-site-scripting-xss-in"},{"cve":"CVE-2022-31057","cvss":3.1,"epss":0.0068,"slug":"cve-2022-31057-authenticated-stored-cross-site-scripting-in-shopware","title":"Authenticated Stored Cross-site Scripting in Shopware","severity":"low","exploited":false,"published_at":"2022-06-22T17:53:34+00:00","url":"https://junglewise.ai/threats/cve-2022-31057-authenticated-stored-cross-site-scripting-in-shopware"},{"cve":"CVE-2019-12935","cvss":3,"epss":0.0273,"slug":"cve-2019-12935-shopware-cross-site-scripting-vulnerability","title":"Shopware Cross-site Scripting Vulnerability","severity":"low","exploited":false,"published_at":"2022-05-24T22:00:09+00:00","url":"https://junglewise.ai/threats/cve-2019-12935-shopware-cross-site-scripting-vulnerability"},{"cve":"CVE-2019-12799","cvss":3,"epss":0.5468,"slug":"cve-2019-12799-shopware-insecure-deserialization-vulnerability","title":"Shopware Insecure Deserialization Vulnerability","severity":"low","exploited":false,"published_at":"2022-05-24T16:48:00+00:00","url":"https://junglewise.ai/threats/cve-2019-12799-shopware-insecure-deserialization-vulnerability"},{"cve":"CVE-2017-15374","cvss":3,"epss":0.0481,"slug":"cve-2017-15374-shopware-xss-vulnerability","title":"Shopware XSS Vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T03:49:04+00:00","url":"https://junglewise.ai/threats/cve-2017-15374-shopware-xss-vulnerability"},{"cve":"CVE-2018-20713","cvss":3,"epss":0.0111,"slug":"cve-2018-20713-shopware-sql-injection","title":"Shopware SQL Injection","severity":"low","exploited":false,"published_at":"2022-05-14T01:39:47+00:00","url":"https://junglewise.ai/threats/cve-2018-20713-shopware-sql-injection"},{"cve":"CVE-2017-18357","cvss":3,"epss":0.2707,"slug":"cve-2017-18357-shopware-xxe-vulnerability","title":"Shopware XXE Vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T01:00:48+00:00","url":"https://junglewise.ai/threats/cve-2017-18357-shopware-xxe-vulnerability"},{"cve":"CVE-2022-24892","cvss":3.1,"epss":0.0087,"slug":"cve-2022-24892-multiple-valid-tokens-for-password-reset-in-shopware","title":"Multiple valid tokens for password reset in Shopware","severity":"low","exploited":false,"published_at":"2022-04-28T21:02:17+00:00","url":"https://junglewise.ai/threats/cve-2022-24892-multiple-valid-tokens-for-password-reset-in-shopware"},{"cve":"CVE-2022-24879","cvss":3.1,"epss":0.0061,"slug":"cve-2022-24879-malfunction-of-csrf-token-validation-in-shopware","title":"Malfunction of CSRF token validation in Shopware","severity":"low","exploited":false,"published_at":"2022-04-28T21:01:53+00:00","url":"https://junglewise.ai/threats/cve-2022-24879-malfunction-of-csrf-token-validation-in-shopware"},{"cve":"CVE-2022-24873","cvss":3.1,"epss":0.0079,"slug":"cve-2022-24873-reflected-cross-site-scripting-in-shopware-storefront","title":"Reflected Cross-site Scripting in Shopware storefront","severity":"low","exploited":false,"published_at":"2022-04-28T20:59:24+00:00","url":"https://junglewise.ai/threats/cve-2022-24873-reflected-cross-site-scripting-in-shopware-storefront"},{"cve":"CVE-2022-21651","cvss":3.1,"epss":0.0077,"slug":"cve-2022-21651-open-redirect-in-shopware","title":"Open redirect in shopware","severity":"low","exploited":false,"published_at":"2022-01-06T23:49:19+00:00","url":"https://junglewise.ai/threats/cve-2022-21651-open-redirect-in-shopware"},{"cve":"CVE-2022-21652","cvss":3.1,"epss":0.0079,"slug":"cve-2022-21652-insufficient-session-expiration-in-shopware","title":"Insufficient Session Expiration in shopware","severity":"low","exploited":false,"published_at":"2022-01-06T23:49:17+00:00","url":"https://junglewise.ai/threats/cve-2022-21652-insufficient-session-expiration-in-shopware"},{"cve":"CVE-2021-41188","cvss":3.1,"epss":0.0076,"slug":"cve-2021-41188-authenticated-stored-xss-in-shopware-shopware","title":"Authenticated Stored XSS in shopware/shopware","severity":"low","exploited":false,"published_at":"2021-10-27T18:53:18+00:00","url":"https://junglewise.ai/threats/cve-2021-41188-authenticated-stored-xss-in-shopware-shopware"},{"cve":"CVE-2021-32713","cvss":3.1,"epss":0.0074,"slug":"cve-2021-32713-cross-site-scripting","title":"Cross-site scripting","severity":"low","exploited":false,"published_at":"2021-09-08T18:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32713-cross-site-scripting"},{"cve":"CVE-2021-32712","cvss":3.1,"epss":0.0114,"slug":"cve-2021-32712-exposure-of-sensitive-information-to-an-unauthorized-actor","title":"Exposure of Sensitive Information to an Unauthorized Actor","severity":"low","exploited":false,"published_at":"2021-09-08T17:59:46+00:00","url":"https://junglewise.ai/threats/cve-2021-32712-exposure-of-sensitive-information-to-an-unauthorized-actor"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"wwbn/avideo (Packagist)","slug":"wwbn-avideo","vulnerabilities":169,"url":"https://junglewise.ai/threats/technologies/wwbn-avideo"},{"name":"getgrav/grav (Packagist)","slug":"getgrav-grav","vulnerabilities":144,"url":"https://junglewise.ai/threats/technologies/getgrav-grav"},{"name":"thorsten/phpmyfaq (Packagist)","slug":"thorsten-phpmyfaq","vulnerabilities":138,"url":"https://junglewise.ai/threats/technologies/thorsten-phpmyfaq"},{"name":"pimcore/pimcore (Packagist)","slug":"pimcore-pimcore","vulnerabilities":136,"url":"https://junglewise.ai/threats/technologies/pimcore-pimcore"},{"name":"dolibarr/dolibarr (Packagist)","slug":"dolibarr-dolibarr","vulnerabilities":125,"url":"https://junglewise.ai/threats/technologies/dolibarr-dolibarr"},{"name":"drupal/core (Packagist)","slug":"packagist-drupal-core","vulnerabilities":116,"url":"https://junglewise.ai/threats/technologies/packagist-drupal-core"},{"name":"librenms/librenms (Packagist)","slug":"librenms-librenms","vulnerabilities":113,"url":"https://junglewise.ai/threats/technologies/librenms-librenms"},{"name":"microweber/microweber (Packagist)","slug":"microweber-microweber","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/microweber-microweber"},{"name":"concrete5/concrete5 (Packagist)","slug":"concrete5-concrete5","vulnerabilities":93,"url":"https://junglewise.ai/threats/technologies/concrete5-concrete5"},{"name":"craftcms/cms (Packagist)","slug":"craftcms-cms","vulnerabilities":90,"url":"https://junglewise.ai/threats/technologies/craftcms-cms"},{"name":"snipe/snipe-it (Packagist)","slug":"snipe-snipe-it","vulnerabilities":80,"url":"https://junglewise.ai/threats/technologies/snipe-snipe-it"},{"name":"phpmyfaq/phpmyfaq (Packagist)","slug":"phpmyfaq-phpmyfaq","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/phpmyfaq-phpmyfaq"}],"technology":{"hub":true,"name":"shopware/shopware (Packagist)","slug":"shopware-shopware","vendor":{"name":"Packagist","slug":"packagist","url":"https://junglewise.ai/threats/vendors/packagist"},"aliases":[],"homepage":"https://www.shopware.com/","repo_url":"https://github.com/shopware/shopware","description":"An open-source e-commerce platform based on Symfony and Vue.js.","url":"https://junglewise.ai/threats/technologies/shopware-shopware"},"most_severe":[{"cvss":5.3,"slug":"shopware-sensitive-file-exposure-via-incorrect-web-root-configuration-ff4bd75f","title":"Shopware sensitive file exposure via incorrect web root configuration","severity":"medium","exploited":false,"published_at":"2021-04-13T15:13:37+00:00","url":"https://junglewise.ai/threats/shopware-sensitive-file-exposure-via-incorrect-web-root-configuration-ff4bd75f"},{"cve":"CVE-2021-32712","cvss":3.1,"epss":0.0114,"slug":"cve-2021-32712-exposure-of-sensitive-information-to-an-unauthorized-actor","title":"Exposure of Sensitive Information to an Unauthorized Actor","severity":"low","exploited":false,"published_at":"2021-09-08T17:59:46+00:00","url":"https://junglewise.ai/threats/cve-2021-32712-exposure-of-sensitive-information-to-an-unauthorized-actor"},{"cve":"CVE-2022-24892","cvss":3.1,"epss":0.0087,"slug":"cve-2022-24892-multiple-valid-tokens-for-password-reset-in-shopware","title":"Multiple valid tokens for password reset in Shopware","severity":"low","exploited":false,"published_at":"2022-04-28T21:02:17+00:00","url":"https://junglewise.ai/threats/cve-2022-24892-multiple-valid-tokens-for-password-reset-in-shopware"},{"cve":"CVE-2022-24873","cvss":3.1,"epss":0.0079,"slug":"cve-2022-24873-reflected-cross-site-scripting-in-shopware-storefront","title":"Reflected Cross-site Scripting in Shopware storefront","severity":"low","exploited":false,"published_at":"2022-04-28T20:59:24+00:00","url":"https://junglewise.ai/threats/cve-2022-24873-reflected-cross-site-scripting-in-shopware-storefront"},{"cve":"CVE-2022-21652","cvss":3.1,"epss":0.0079,"slug":"cve-2022-21652-insufficient-session-expiration-in-shopware","title":"Insufficient Session Expiration in shopware","severity":"low","exploited":false,"published_at":"2022-01-06T23:49:17+00:00","url":"https://junglewise.ai/threats/cve-2022-21652-insufficient-session-expiration-in-shopware"},{"cve":"CVE-2022-36102","cvss":3.1,"epss":0.0078,"slug":"cve-2022-36102-shopware-access-control-list-bypassed-via-crafted-specific-urls","title":"Shopware access control list bypassed via crafted specific URLs","severity":"low","exploited":false,"published_at":"2022-09-16T21:01:29+00:00","url":"https://junglewise.ai/threats/cve-2022-36102-shopware-access-control-list-bypassed-via-crafted-specific-urls"},{"cve":"CVE-2022-21651","cvss":3.1,"epss":0.0077,"slug":"cve-2022-21651-open-redirect-in-shopware","title":"Open redirect in shopware","severity":"low","exploited":false,"published_at":"2022-01-06T23:49:19+00:00","url":"https://junglewise.ai/threats/cve-2022-21651-open-redirect-in-shopware"},{"cve":"CVE-2021-41188","cvss":3.1,"epss":0.0076,"slug":"cve-2021-41188-authenticated-stored-xss-in-shopware-shopware","title":"Authenticated Stored XSS in shopware/shopware","severity":"low","exploited":false,"published_at":"2021-10-27T18:53:18+00:00","url":"https://junglewise.ai/threats/cve-2021-41188-authenticated-stored-xss-in-shopware-shopware"},{"cve":"CVE-2021-32713","cvss":3.1,"epss":0.0074,"slug":"cve-2021-32713-cross-site-scripting","title":"Cross-site scripting","severity":"low","exploited":false,"published_at":"2021-09-08T18:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32713-cross-site-scripting"},{"cve":"CVE-2022-36101","cvss":3.1,"epss":0.0068,"slug":"cve-2022-36101-shopware-contains-sensitive-data-in-backend-customer-module","title":"Shopware contains sensitive data in backend customer module","severity":"low","exploited":false,"published_at":"2022-09-16T21:02:55+00:00","url":"https://junglewise.ai/threats/cve-2022-36101-shopware-contains-sensitive-data-in-backend-customer-module"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}