CVE-2025-30151
HIGHShopware < 6.5.8.17 and 6.6.0.0-6.6.10.3 - Denial of Service via Long Password Input
Title source: llmDescription
Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://github.com/shopware/shopware/security/advisories/GHSA-cgfj-hj93-rmh2
Scores
CVSS v3
7.5
EPSS
0.0034
EPSS Percentile
25.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (4)
shopware/core
6.6.0.0 - 6.6.10.3Packagist
shopware/platform
6.6.0.0 - 6.6.10.3Packagist
shopware/shopware
6.7.0.0 rc1
shopware/shopware
< 6.5.8.17
Published
Apr 08, 2025
Tracked Since
Feb 18, 2026