Package impact
Packagist / shopware/storefront
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-67648 | unknown | — | — | 6mo ago | Shopware Storefront Reflected XSS in Storefront Login Page | |||
| CVE-2024-27917 | unknown | — | — | 2y ago | Shopware's session is persistent in Cache for 404 pages | |||
| CVE-2022-24747 | unknown | — | — | 4y ago | HTTP caching is marking private HTTP headers as public in Shopware | |||
| CVE-2022-24746 | unknown | — | — | 4y ago | HTML injection possibility in voucher code form in Shopware | |||
| CVE-2022-24745 | unknown | — | — | 4y ago | Shopware guest session is shared between customers |