ZeroHour

CVE-2026-23498

CVSS 3.1
7.2 high
EPSS
<1%p36
Published
()
Modified
Description

Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure not checked being against allow list for the map(...) override. This vulnerability is fixed in 6.7.6.1.

Vendors
shopware
Products
shopware
Ecosystems
E-commerce
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.