These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-48016 is a vulnerability in Shopware, an open commerce platform. The Store API endpoint /store-api/handle-payment accepts a user-controlled orderId and forwards it without verifying order ownership or guest-order authentication. This allows a normal customer or guest context to trigger the payment flow for another user's order. The issue is fixed in versions 6.6.10.18 and 6.7.10.1. The vulnerabil [truncated]
CVE-2026-48015 is a vulnerability in the Shopware open commerce platform that allows malicious SVG file uploads. Prior to versions 6.6.10.18 and 6.7.10.1, SVG files were included in the allowed_extensions whitelist in shopware.yaml, enabling uploads via the media manager without proper SVG content sanitization. This could lead to the execution of malicious SVG JavaScript, such as onload, <script>, and <fo [truncated]
CVE-2026-48014 is a medium-severity vulnerability affecting Shopware, an open commerce platform. The vulnerability exists in the order state transition features, specifically in the /api/_action/order/{orderId}/state/{transition} and similar transaction and delivery transition routes. These routes do not declare PlatformRequest::ATTRIBUTE_ACL or perform an explicit privilege check, allowing low-privileged [truncated]
CVE-2026-48010 is a vulnerability in Shopware's open commerce platform that allows non-admin API users to set admin privileges on new or existing users due to a lack of filtering in the UserController::upsertUser() function. This issue has a CVSS score of 6.5 and a severity of MEDIUM. Affected deployments exist in managed environments, requiring owners to review and mitigate the vulnerability. The issue i [truncated]
CVE-2026-48009 is a vulnerability in Shopware, an open commerce platform. A low-privilege admin user with user_recovery:read ACL can take over any admin account by exploiting the user recovery API. This issue is fixed in versions 6.6.10.18 and 6.7.10.1. The vulnerability allows an attacker to trigger a password recovery, read the recovery hash, and use it to take over an admin account. The root cause is t [truncated]
CVE-2026-48008 is a medium-severity vulnerability in Shopware, an open commerce platform. A non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API. This issue is fixed in versions 6.6.10.18 and 6.7.10.1. The vulnerability exists due to the lack of WriteProtection on the admin field in the IntegrationDefin [truncated]
CVE-2026-48011 is a low-severity vulnerability in Shopware, a popular open commerce platform. The issue, with a CVSS score of 3.7, allows an attacker to enumerate the usernames of administrator users by performing a timing attack. This vulnerability was published on June 10, 2026, and modified on June 11, 2026. The attack requires no privileges (PR:N) and has a low impact on confidentiality (C:L). The vul [truncated]