HIGH🇵🇱 Wersja polska

CVE-2026-31887

CVSS 8.9v4.0pub. 2026-03-11upd. 2026-03-16

Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability is fixed in 6.7.8.1 and 6.6.10.15.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Shopware

    APP
    Shopware
    < 6.6.10.156.7.0.0 – 6.7.8.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-22406CRITICAL9.3PL ✓same product

SQL injection w API wyszukiwania Shopware przez pole 'name' agregacji

CVE-2023-22731CRITICAL9.9PL ✓same product

Shopware: RCE przez wykonanie dowolnego kodu PHP w filtrach Twig

CVE-2021-32711CRITICAL9.1PL ✓same product

Shopware Store-API — wyciek informacji (information disclosure)

CVE-2016-3109CRITICAL9.8PL ✓same product

RCE w Shopware — podatny skrypt backend/Login/load/

CVE-2026-31889HIGH8.9same product

Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app reg...