Confidence
Medium. Based on ~20 public sources; many review snippets were truncated, lowering quote availability.
Pricing
Free (self-hosted)
Rise
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
EvolveFrom $600/mo
BeyondCustom quote
Sources & method
Analyzed 9/19/2026 - 9 sources - Active CVE history — XSS, privilege escalation, admin takeover — all patched, but self-hosters must stay current.
official x2review x4security x2news x1
- Store API admin takeover vulnerability, A vulnerability allowed administrator takeover; Shopware fixed it after researcher disclosure.
- CVE-2026-48008 — privilege escalation, A privilege escalation vulnerability was disclosed in the Shopware vulnerability database.
- App credential takeover (GHSA-c4p7-rwrg-pf6p), Shopware was vulnerable to potential takeover of app credentials, per its own GitHub advisory.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.