shopware/platform Security Advisories for v6.6.7.1 (11)
- 
                        [MEDIUM] Shopware Customer Orders can be canceled, even if refunds are disabledPKSA-g23j-x3sb-wcbc GHSA-r2vg-hvjm-fg38 Affected version: <6.6.10.7|>=6.7.0.0,<6.7.3.1 Reported by: 
 GitHub
- 
                        [MEDIUM] Shopware exposes sensitive user information via CSV export mappingPKSA-cb17-wqsx-y85w GHSA-27c9-vp3w-6ww8 Affected version: <6.6.10.7|>=6.7.0.0,<6.7.3.1 Reported by: 
 GitHub
- 
                        [LOW] Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoicePKSA-ph5g-5w5h-nqtz GHSA-3cpp-fv95-mpr5 Affected version: <6.6.10.7|>=6.7.0.0,<6.7.3.1 Reported by: 
 GitHub
- 
                        [LOW] Shopware vulnerable to path traversal via Plugin uploadPKSA-wg2b-w14d-z55p GHSA-6wh5-mw9h-5c3w Affected version: <6.6.10.7|>=6.7.0.0,<6.7.3.1 Reported by: 
 GitHub
- 
                        [MEDIUM] Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individuallyPKSA-h7xc-cnc9-hq4s GHSA-m895-2hj3-8cg9 Affected version: <6.6.10.7|>=6.7.0.0,<6.7.3.1 Reported by: 
 GitHub
- 
                        [MEDIUM] Shopware race condition bypasses voucher restrictionsPKSA-sy2r-ddrd-9s1c CVE-2025-7954 GHSA-27gv-mg7w-mm34 Affected version: <=6.6.10.4 Reported by: 
 GitHub
- 
                        [LOW] Shopware default newsletter opt-in settings allow for mass sign-up abusePKSA-7zw7-y79b-kv9s CVE-2025-32378 GHSA-4h9w-7vfp-px8m Affected version: <6.5.8.17|>=6.7.0.0-rc1,<6.7.0.0-rc2|>=6.6.0.0-rc1,<6.6.10.3 Reported by: 
 GitHub
- 
                        [MEDIUM] Shopware Broken ACL on Document retrieval to access other customers documentsPKSA-9qy7-f7jp-k813 GHSA-68wv-g3fw-pq7q Affected version: <6.5.8.17|>=6.7.0.0-rc1,<6.7.0.0-rc2|>=6.6.0.0,<6.6.10.3 Reported by: 
 GitHub
- 
                        [HIGH] Shopware Vulnerable to Blind SQL-injection in DAL aggregationsPKSA-fkd6-58gd-wqfz CVE-2025-27892 GHSA-8g35-7rmw-7f59 Affected version: <6.5.8.18|>=6.6.0.0,<=6.6.10.2|=6.7.0.0-rc1 Reported by: 
 GitHub
- 
                        [HIGH] Shopware allows Denial Of Service via password lengthPKSA-qf2k-hv7v-9bz9 CVE-2025-30151 GHSA-cgfj-hj93-rmh2 Affected version: <6.5.8.17|>=6.7.0.0-rc1,<6.7.0.0-rc2|>=6.6.0.0,<6.6.10.3 Reported by: 
 GitHub
- 
                        [MEDIUM] Shopware 6 allows attackers to check for registered accounts through the store-apiPKSA-4xth-xj4w-m8t1 CVE-2025-30150 GHSA-hh7j-6x3q-f52h Affected version: <=6.5.8.17|>=6.6.0.0,<=6.6.10.2|=6.7.0.0-rc1 Reported by: 
 GitHub