cvedb.io
CVE-2025-67648
HIGH · CVSS 7.1
EPSS exploitation probability: 0%
Published 2025-12-11T00:16:23.557 · Last modified 2026-06-17T09:57:59.227

Summary

Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template of the Storefront login page without further processing or input validation. This allows direct code injection into the template via the URL parameter, waitTime, which lacks proper input validation. This issue is fixed in versions 6.6.10.10 and 6.7.5.1.

Affected products

shopware — shopware

Does this affect you?

Add your gear to cvedb and we'll alert you only when shopware ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.