CVE-2026-48015

Source
https://cve.org/CVERecord?id=CVE-2026-48015
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48015.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-48015
Aliases
Published
2026-07-17T17:53:01Z
Modified
2026-08-12T03:51:14Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Shopware: Stored XSS via SVG file upload — no SVG sanitization
Details

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via the media manager without SVG content sanitization in the upload pipeline from MediaUploadController to FileSaver to TypeDetector, allowing malicious SVG JavaScript such as onload,

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48015.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "6.6.10.18"
                },
                {
                    "fixed": "6.6.10.18"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/shopware/shopware

Affected ranges

Type
GIT
Repo
https://github.com/shopware/shopware
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "6.7.0.0"
        },
        {
            "fixed": "6.7.10.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48015.json"