PT-2026-25040 · Shopware · Commercial
Amenk
·
Published
2026-03-12
·
Updated
2026-03-13
·
CVE-2026-32142
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Shopware versions prior to 7.8.1
Shopware versions prior to 6.10.15
Description
Shopware is an open commerce platform. The
/api/ info/config API endpoint exposes information about licenses. This allows for unauthenticated information disclosure.Recommendations
Update to Shopware version 7.8.1 or later.
Update to Shopware version 6.10.15 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Commercial