Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template of the Storefront login page without further processing or input validation. This allows direct code injection into the template via the URL parameter, waitTime, which lacks proper input validation. This issue is fixed in versions 6.6.10.10 and 6.7.5.1.
History

Thu, 11 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Dec 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Shopware
Shopware shopware
Vendors & Products Shopware
Shopware shopware

Thu, 11 Dec 2025 00:00:00 +0000

Type Values Removed Values Added
Description Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template of the Storefront login page without further processing or input validation. This allows direct code injection into the template via the URL parameter, waitTime, which lacks proper input validation. This issue is fixed in versions 6.6.10.10 and 6.7.5.1.
Title Shopware's inproper input validation can lead to Reflected XSS through Storefront Login Page
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-10T23:55:10.060Z

Updated: 2025-12-11T19:00:14.044Z

Reserved: 2025-12-09T18:36:41.331Z

Link: CVE-2025-67648

cve-icon Vulnrichment

Updated: 2025-12-11T19:00:09.520Z

cve-icon NVD

Status : Received

Published: 2025-12-11T00:16:23.557

Modified: 2025-12-11T00:16:23.557

Link: CVE-2025-67648

cve-icon Redhat

No data.