Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability is fixed in 6.7.8.1 and 6.6.10.15.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShopware
APPShopware< 6.6.10.156.7.0.0 – 6.7.8.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2024-22406CRITICAL9.3PL ✓same product
SQL injection w API wyszukiwania Shopware przez pole 'name' agregacji
CVE-2023-22731CRITICAL9.9PL ✓same product
Shopware: RCE przez wykonanie dowolnego kodu PHP w filtrach Twig
CVE-2021-32711CRITICAL9.1PL ✓same product
Shopware Store-API — wyciek informacji (information disclosure)
CVE-2016-3109CRITICAL9.8PL ✓same product
RCE w Shopware — podatny skrypt backend/Login/load/
CVE-2026-31889HIGH8.9same product
Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app reg...