{"id":"CVE-2025-30150","aliases":["GHSA-hh7j-6x3q-f52h"],"url":"https://o3.security/vulnerability/CVE-2025-30150","summary":"Shopware 6 allows attackers to check for registered accounts through the store-api","details":"Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api endpoint /store-api/account/recovery-password you get the response, which indicates clearly that there is no account for this customer. In contrast you get a success response if the account was found. This vulnerability is fixed in Shopware 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.","published":"2025-04-08T13:46:44.823Z","modified":"2026-08-12T03:51:34.704970194Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"shopware/core","fixedVersion":"6.6.10.3"},{"ecosystem":"Packagist","name":"shopware/platform","fixedVersion":"6.6.10.3"},{"ecosystem":"Packagist","name":"shopware/core","fixedVersion":"6.7.0.0-rc2"},{"ecosystem":"Packagist","name":"shopware/platform","fixedVersion":"6.7.0.0-rc2"},{"ecosystem":"Packagist","name":"shopware/core","fixedVersion":"6.5.8.18"},{"ecosystem":"Packagist","name":"shopware/platform","fixedVersion":"6.5.8.18"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30150.json"},{"type":"ADVISORY","url":"https://github.com/shopware/shopware/security/advisories/GHSA-hh7j-6x3q-f52h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30150"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:34.704970194Z"}}