Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48015

Опубликовано: 17 июл. 2026
Источник: nvd
CVSS3: 4.9
EPSS Низкий

Описание

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via the media manager without SVG content sanitization in the upload pipeline from MediaUploadController to FileSaver to TypeDetector, allowing malicious SVG JavaScript such as onload,

EPSS

Процентиль: 20%
0.00278
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.9
github
2 месяца назад

Shopware: Stored XSS via SVG file upload — no SVG sanitization

EPSS

Процентиль: 20%
0.00278
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-79