{"id":"CVE-2022-31057","aliases":[],"url":"https://o3.security/vulnerability/CVE-2022-31057","summary":"Shopware is an open source e-commerce software made in Germany. Versions of Shopware 5 prior to version 5.7.12 are subject to an authenticated Stored XSS in Administration. Users are…","details":"Shopware is an open source e-commerce software made in Germany. Versions of Shopware 5 prior to version 5.7.12 are subject to an authenticated Stored XSS in Administration. Users are advised to upgrade. There are no known workarounds for this issue.","published":"2022-06-27T20:15:08.527","modified":"2026-06-17T04:44:42.300","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/shopware/shopware/commit/3e025a0a3e123f4108082645b1ced6fb548f7b6f","label":"shopware/shopware@3e025a0"},"references":[{"type":"ADVISORY","url":"https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-06-2022"},{"type":"FIX","url":"https://github.com/shopware/shopware/commit/3e025a0a3e123f4108082645b1ced6fb548f7b6f"},{"type":"ADVISORY","url":"https://github.com/shopware/shopware/security/advisories/GHSA-q754-vwc4-p6qj"},{"type":"ADVISORY","url":"https://packagist.org/packages/shopware/shopware"},{"type":"ADVISORY","url":"https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-06-2022"},{"type":"FIX","url":"https://github.com/shopware/shopware/commit/3e025a0a3e123f4108082645b1ced6fb548f7b6f"},{"type":"ADVISORY","url":"https://github.com/shopware/shopware/security/advisories/GHSA-q754-vwc4-p6qj"},{"type":"ADVISORY","url":"https://packagist.org/packages/shopware/shopware"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T04:44:42.300"}}