CVE-2017-18357: Shopware
Medium severity, CVSS 6.5. EPSS: 27.1% chance of exploitation in the next 30 days.
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.
Affected products
- Shopware Shopware: before 5.3.4 (fixed in 5.3.4)
Published 2019-01-15. Last modified 2026-06-17.