CVE-2025-30151

HIGH

Shopware < 6.5.8.17 and 6.6.0.0-6.6.10.3 - Denial of Service via Long Password Input

Title source: llm
STIX 2.1

Description

Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0034
EPSS Percentile 25.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (4)
shopware/core 6.6.0.0 - 6.6.10.3Packagist
shopware/platform 6.6.0.0 - 6.6.10.3Packagist
shopware/shopware 6.7.0.0 rc1
shopware/shopware < 6.5.8.17
Published Apr 08, 2025
Tracked Since Feb 18, 2026