PT-2026-25040 · Shopware · Commercial

Amenk

·

Published

2026-03-12

·

Updated

2026-03-13

·

CVE-2026-32142

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Shopware versions prior to 7.8.1 Shopware versions prior to 6.10.15
Description Shopware is an open commerce platform. The /api/ info/config API endpoint exposes information about licenses. This allows for unauthenticated information disclosure.
Recommendations Update to Shopware version 7.8.1 or later. Update to Shopware version 6.10.15 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-32142
GHSA-GVMV-9F74-MHWP

Affected Products

Commercial