CVE-2025-27892
MEDIUM NUCLEIShopware < 6.5.8.13 - SQL Injection
Title source: nucleiDescription
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.
Nuclei Templates (1)
Shopware < 6.5.8.13 - SQL Injection
CRITICALVERIFIEDby iamnoooob,rootxharsh,pdresearch
Scores
CVSS v3
6.8
EPSS
0.0279
EPSS Percentile
86.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
Details
CWE
CWE-89
Status
published
Products (4)
shopware/core
6.7.0.0-rc1 - 6.7.0.0-rc2Packagist
shopware/platform
6.7.0.0-rc1 - 6.7.0.0-rc2Packagist
shopware/shopware
6.7.0.0 rc1
shopware/shopware
< 6.5.8.17
Published
Apr 15, 2025
Tracked Since
Feb 18, 2026