Vulnerabilities (CVE)

Filtered by vendor Shopware Subscribe
Filtered by product Shopware
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-37708 1 Shopware 1 Shopware 2021-08-24 7.5 HIGH 9.8 CRITICAL
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
CVE-2016-3109 1 Shopware 1 Shopware 2018-10-09 10.0 HIGH 9.8 CRITICAL
The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.