Vulnerabilities
Report: CVE-2026-31887 - Shopware unauthenticated data extraction possible through store-api.order endpoint
CVE ID :CVE-2026-31887 Published : March 11, 2026, 6:49 p.m. | 35 minutes ago Description :Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability is fixed in 6.7.8.1 and 6.6.10.15. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
CVE ID
Published
March 11, 2026