Exploitation Summary
CVE-2025-27892 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.
Nuclei Templates (1)
Shopware < 6.5.8.13 - SQL Injection
CRITICALVERIFIEDby iamnoooob,rootxharsh,pdresearch
References (2)
Core 2
Core References
Scores
CVSS v3
6.8
EPSS
0.1141
EPSS Percentile
95.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (4)
shopware/core
6.7.0.0-rc1 - 6.7.0.0-rc2Packagist
shopware/platform
6.7.0.0-rc1 - 6.7.0.0-rc2Packagist
shopware/shopware
6.7.0.0 rc1
shopware/shopware
< 6.5.8.17
Published
Apr 15, 2025
Tracked Since
Feb 18, 2026