← Back

CVE-2025-67648

nvd nist
Published: Dec 11, 2025Modified: Mar 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template of the Storefront login page without further processing or input validation. This allows direct code injection into the template via the URL parameter, waitTime, which lacks proper input validation. This issue is fixed in versions 6.6.10.10 and 6.7.5.1.

Affected (2)

Products: Shopware: Shopware
1 product
Shopware
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Shopware
From 6.4.6.0 to 6.6.10.10
From 6.7.0.0 to 6.7.5.1

References (2)

Timeline

No history available yet.