IA Squad
SearchPT

shopware/platform

php · shopware/platformCritical

Shopware Platform: Privilege Escalation via Sync API Bypass

A non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admi

09 Jun 2026 · act now
php · shopware/platformCritical

Shopware Platform: user_recovery hash exposed via Admin API

The `user_recovery` entity exposes its `hash` field through the Admin API search endpoint (`POST /api/search/user-recovery`), allo

09 Jun 2026 · act now
php · shopware/platformCritical

shopware/platform: Non-admin users can escalate to admin via UserController::upsertUser()

UserController::upsertUser() writes user data in SYSTEM_SCOPE and does not filter the admin field, allowing non-admin API users wi

09 Jun 2026 · act now
php · shopware/platformHeads-up

shopware/platform OAuth user repository timing attack vulnerability

A timing attack vulnerability in the OAuth user repository allows enumeration of administrator usernames.

09 Jun 2026 · schedule it
php · shopware/platformHeads-up

shopware/platform: Missing ACL checks on order state transition endpoints

Order state transition endpoints in the Admin API are missing ACL privilege checks, allowing low-privileged users to change order

09 Jun 2026 · schedule it
php · shopware/platformHeads-up

shopware/platform: Missing authorization in /store-api/handle-payment

The Store API endpoint `/store-api/handle-payment` lacks object-level authorization, allowing a low-privileged user to trigger pay

09 Jun 2026 · schedule it