Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. shopware/core
  4. ›
  5. GHSA-9v82-vcjx-m76j

GHSA-9v82-vcjx-m76j: Shopware: Reflective Cross Site-Scripting (XSS) in CMS components

September 10, 2025

When an application uses input fields, it is important that user input is adequately filtered for malicious HTML and JavaScript characters. When adequate input validation is not applied, Cross-Site Scripting (XSS) vulnerabilities may arise. These allow malicious actors to inject malicious code into application pages. When a user visits the page, the code is executed in the user’s web browser. This allows malicious actors to perform malicious actions in the name of that user. XSS can be divided into three variants: Persistent XSS, Reflective XSS and DOM-based XSS. In Reflective XSS, a malicious actor injects malicious JavaScript code into a URL. Every time the user visits this URL, the JavaScript code is executed in the user’s browser.

References

  • github.com/advisories/GHSA-9v82-vcjx-m76j
  • github.com/shopware/shopware
  • github.com/shopware/shopware/commit/12fb537c5ebe009f2a0f58b9c24dbd2d6b4c508f
  • github.com/shopware/shopware/releases/tag/v6.7.2.1
  • github.com/shopware/shopware/security/advisories/GHSA-9v82-vcjx-m76j

Code Behaviors & Features

Detect and mitigate GHSA-9v82-vcjx-m76j with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 6.7.0.0 before 6.7.2.1

Fixed versions

  • 6.7.2.1

Solution

Upgrade to version 6.7.2.1 or above.

Impact 8.8 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

packagist/shopware/core/GHSA-9v82-vcjx-m76j.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 25 Sep 2025 12:20:08 +0000.