Account Enumeration Vulnerability in Shopware 6 by Shopware
CVE-2025-30150
What is CVE-2025-30150?
Shopware 6, a widely used commerce platform, is susceptible to an account enumeration vulnerability through its store-api. Attackers can exploit the endpoint /store-api/account/recovery-password to ascertain whether a specific email address is registered with an account. The response differentiates based on account existence: a clear indication of no account exists for the former, while returning a success message if an account is indeed found. This creates a potential risk for user data exposure. Users are strongly encouraged to upgrade to the latest versions, Shopware 6.6.10.3 or 6.5.8.17, to mitigate this risk. For those on the older version 6.4, corresponding security measures are available through a dedicated plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
shopware < 6.5.8.17 < 6.5.8.17
shopware >= 6.6.0.0, < 6.6.10.3 < 6.6.0.0, 6.6.10.3
shopware >= 6.7.0.0-rc1, < 6.7.0.0-rc2 < 6.7.0.0-rc1, 6.7.0.0-rc2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
