CVE-2025-27892
15.04.2025, 22:15
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.
Vendor | Product | Version |
---|---|---|
shopware | shopware | 𝑥 < 6.5.8.17 |
shopware | shopware | 6.6.0.0 ≤ 𝑥 < 6.6.10.3 |
shopware | shopware | 6.7.0.0:rc1 |
𝑥
= Vulnerable software versions