github.com
https://github.com/shopware/shopware CVE-2025-30151
HIGH
Shopware allows Denial Of Service via password length
Record summary
CVE-2025-30151 has a selected CVSS score of 7.5 (high).
Description
Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 8, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
shopwareBrowse shopware / shopware | CVE List | < 6.5.8.17 | affected |
| >= 6.6.0.0, < 6.6.10.3 | affected | ||
| >= 6.7.0.0-rc1, < 6.7.0.0-rc2 | affected | ||
shopware/coreBrowse Packagist / shopware/core | GitHub Advisory | 6.6.0.0 to < 6.6.10.3 · Fixed in 6.6.10.3 | affected |
| 6.7.0.0-rc1 to < 6.7.0.0-rc2 · Fixed in 6.7.0.0-rc2 | affected | ||
| Before 6.5.8.17 · Fixed in 6.5.8.17 | affected | ||
shopware/platformBrowse Packagist / shopware/platform | GitHub Advisory | 6.6.0.0 to < 6.6.10.3 · Fixed in 6.6.10.3 | affected |
| 6.7.0.0-rc1 to < 6.7.0.0-rc2 · Fixed in 6.7.0.0-rc2 | affected | ||
| Before 6.5.8.17 · Fixed in 6.5.8.17 | affected |
References
6github.com
https://github.com/shopware/shopware/releases/tag/v6.5.8.17 github.com
https://github.com/shopware/shopware/releases/tag/v6.6.10.3 github.com
https://github.com/shopware/shopware/releases/tag/v6.7.0.0-rc2 github.comConfirmation
https://github.com/shopware/shopware/security/advisories/GHSA-cgfj-hj93-rmh2 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-30151