CVE-2026-32142: Shopware Commercial

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is fixed in 7.8.1 and 6.10.15.

Affected products

  • Shopware Commercial: from 7.0.0, before 7.8.1 (fixed in 7.8.1); before 6.10.15 (fixed in 6.10.15)

Published 2026-03-12. Last modified 2026-06-17.