Shopware · Froshadminer · CVE-2026-25878
**Name of the Vulnerable Software and Affected Versions**
FroshAdminer versions prior to 2.2.1
**Description**
The Adminer route ('/admin/adminer') within the FroshAdminer plugin for Shopware Platform was accessible without requiring Shopware admin authentication. The route was configured without authentication and session validation, potentially exposing the Adminer user interface to unauthorized users.
**Recommendations**
Update FroshAdminer to version 2.2.1 or later.