{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-14T10:08:10.583","vulnerabilities":[{"cve":{"id":"CVE-2022-24873","sourceIdentifier":"security-advisories@github.com","published":"2022-04-28T14:15:07.663","lastModified":"2024-11-21T06:51:17.737","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin."},{"lang":"es","value":"Shopware es una plataforma de software de comercio electrónico de código abierto. En versiones anteriores a 5.7.9, Shopware era vulnerable a un ataque de tipo cross-site scripting no almacenado en la tienda. Este problema ha sido corregido en versión 5.7.9. Los usuarios de versiones anteriores pueden intentar mitigar la vulnerabilidad usando el plugin de seguridad de Shopware"}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0","versionEndExcluding":"5.7.9","matchCriteriaId":"0F0DF13B-4EDD-4F64-93E6-C046BE98C8F9"}]}]}],"references":[{"url":"https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-04-2022","source":"security-advisories@github.com","tags":["Vendor Advisory"]},{"url":"https://github.com/shopware/shopware/security/advisories/GHSA-4g29-fccr-p59w","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://www.shopware.com/en/changelog-sw5/#5-7-9","source":"security-advisories@github.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-04-2022","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://github.com/shopware/shopware/security/advisories/GHSA-4g29-fccr-p59w","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.shopware.com/en/changelog-sw5/#5-7-9","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}}]}