CVE-2026-48013 | Shopware prior 6.6.10.18/6.7.10.1 Link URL Flow external-link server-side request forgery
A vulnerability classified as problematic has been found in Shopware. This impacts an unknown function of the file /api/_action/media/external-link of the component Link URL Flow. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-48013. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More