Soner Sayakci
28 exploits
Active since Jun 2021
Shopware 6.3.5.0-6.5.8.7 - Insufficient Session Expiration via Store-API Logout
CVSS 5.3
Shopware < 6.5.8.13 - Improper Access Control via ManyToMany Association Handling
CVSS 5.3
Shopware < 6.5.8.13 - Improper Access Control via ManyToMany Association Handling
CVSS 5.3
Shopware <6.6.5.1-6.5.8.13 - Code Injection
CVSS 8.3
Shopware <6.6.5.1-6.5.8.13 - Code Injection
CVSS 8.3
Shopware <6.6.5.1-6.5.8.13 - Code Injection
CVSS 8.3
Shopware <6.6.5.1-6.5.8.13 - Code Injection
CVSS 8.3
Shopware < 6.5.8.13 - SQL Injection via Aggregation Name Parameter
CVSS 7.3
Shopware < 6.5.8.13 - SQL Injection via Aggregation Name Parameter
CVSS 7.3
Shopware <6.4.1.1 - Info Disclosure
CVSS 4.4
Shopware < 6.4.3.1 - Product Review Manipulation via API
CVSS 6.5
Shopware < 6.4.3.1 - OS Command Injection in Mail Agent Settings
CVSS 8.8
Shopware < 6.4.3.1 - Insecure Direct Object Reference in Import/Export Log Files
CVSS 6.5
Shopware <6.4.8.2 - Info Disclosure
CVSS 6.3
Shopware < 6.4.10.1 - Server-Side Request Forgery via Admin SDK
CVSS 7.2
Shopware < 6.4.10.1 - Incorrect Permission Assignment for Critical Resource
CVSS 8.1
Shopware < 6.4.18.1 - Authenticated Remote Code Execution via Twig Filter PHP Function Injection
CVSS 9.9
Shopware <6.5.8.0 - Info Disclosure
CVSS 7.5
Shopware <6.5.8.0 - Info Disclosure
CVSS 7.5
Shopware 6.3.5.0-6.5.8.7 - Insufficient Session Expiration via Store-API Logout
CVSS 5.3
Shopware < 6.5.8.13 - Improper Access Control via ManyToMany Association Handling
CVSS 5.3
Shopware < 6.5.8.13 - Improper Access Control via ManyToMany Association Handling
CVSS 5.3
Shopware <6.6.5.1-6.5.8.13 - Code Injection
CVSS 8.3
Shopware <6.6.5.1-6.5.8.13 - Code Injection
CVSS 8.3
Shopware <6.6.5.1-6.5.8.13 - Code Injection
CVSS 8.3