Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10294 | Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression. |
Github GHSA |
GHSA-8g35-7rmw-7f59 | Shopware Vulnerable to Blind SQL-injection in DAL aggregations |
Wed, 23 Apr 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shopware
Shopware shopware |
|
| CPEs | cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:* cpe:2.3:a:shopware:shopware:6.7.0.0:rc1:*:*:*:*:*:* |
|
| Vendors & Products |
Shopware
Shopware shopware |
Wed, 16 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Tue, 15 Apr 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-16T18:32:23.303Z
Reserved: 2025-03-10T00:00:00.000Z
Link: CVE-2025-27892
Updated: 2025-04-16T14:52:47.248Z
Status : Analyzed
Published: 2025-04-15T22:15:25.577
Modified: 2025-04-23T16:30:45.300
Link: CVE-2025-27892
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA