CVE-2025-27892

MEDIUM NUCLEI

Shopware < 6.5.8.13 - SQL Injection

Title source: nuclei

Description

Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.

Nuclei Templates (1)

Shopware < 6.5.8.13 - SQL Injection
CRITICALVERIFIEDby iamnoooob,rootxharsh,pdresearch

Scores

CVSS v3 6.8
EPSS 0.0279
EPSS Percentile 86.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L

Details

CWE
CWE-89
Status published
Products (4)
shopware/core 6.7.0.0-rc1 - 6.7.0.0-rc2Packagist
shopware/platform 6.7.0.0-rc1 - 6.7.0.0-rc2Packagist
shopware/shopware 6.7.0.0 rc1
shopware/shopware < 6.5.8.17
Published Apr 15, 2025
Tracked Since Feb 18, 2026