CVE-2019-12799: Shopware
High severity, CVSS 8.8. EPSS: 54.1% chance of exploitation in the next 30 days.
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.
Affected products
- Shopware Shopware: up to and including 5.6.0
Published 2019-06-13. Last modified 2026-06-17.