Security Advisory

CVE-2025-30151

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-04-08 13:46:30
Last updated 2025-04-08 18:47:54
Assigner GitHub_M
CVSS score 7.5
State PUBLISHED

Description

Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.