CVE-2026-48015

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via the media manager without SVG content sanitization in the upload pipeline from MediaUploadController to FileSaver to TypeDetector, allowing malicious SVG JavaScript such as onload, <script>, and <foreignObject> to execute in the Shopware domain when the uploaded SVG is viewed. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.
Configurations

No configuration.

History

17 Jul 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-17 18:17

Updated : 2026-07-17 19:17


NVD link : CVE-2026-48015

Mitre link : CVE-2026-48015

CVE.ORG link : CVE-2026-48015


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')