CVE-2016-3109: Shopware

Critical severity, CVSS 9.8. EPSS: 28.1% chance of exploitation in the next 30 days.

The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.

Affected products

  • Shopware Shopware: up to and including 5.1.4

Published 2017-04-21. Last modified 2026-06-17.