StackRadar

shopware 2.0.0 Helm chart

robjuz

Scored 14 Sept 2026

Web publishing platform for building blogs and websites.

Version 2.0.0 4 years agodeploys tag 2021.12.10-debian-10-r0 0Artifact Hub

shopware 2.0.0 deploys 6 container images: bitnami/minio, bitnami/bitnami-shell, bitnami/elasticsearch, bitnami/mariadb and 2 more. Across the 1 measured, 239 findings5 critical, 1 high 3 on CISA KEV. The highest contribution is GHSA-x752-qjv4-c4hc in dompdf/dompdf v1.0.2, fixed in 1.2.1.

Radar Score

2,9725143190

239 findings over 1 of 6 images measured

KEV ×3 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

6 images
ImageTagVulnerabilitiesRadar Score
bitnami/minio2021.12.10-debian-10-r0unmeasured
bitnami/bitnami-shell×310-debian-10-r273unmeasured
bitnami/elasticsearch×37.16.0-debian-10-r0unmeasured
bitnami/mariadb10.5.13-debian-10-r0unmeasured
bitnami/redis6.2.6-debian-10-r53unmeasured
shyim/shopware×36.4.6.051431902,972

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

43 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumGO-2024-2687stdlib@go1.20.71.21.9
MediumGHSA-5mv2-rx3q-4w2vtwig/twig@v3.3.33.3.8
MediumGHSA-8g35-7rmw-7f59shopware/core@6.4.6.06.5.8.18
MediumGHSA-3cw5-7cxw-v5qgdompdf/dompdf@v1.0.22.0.2
MediumGHSA-v9qv-c7wm-wgmfcomposer/composer@2.1.112.2.24
MediumGHSA-6x28-7h8c-chx4dompdf/dompdf@v1.0.22.0.1
MediumGHSA-7v2v-9rm4-7m8fshopware/core@6.4.6.06.4.20.1
MediumGHSA-577p-7j7h-2jgfdompdf/dompdf@v1.0.22.0.0
MediumGHSA-93cw-f5jj-x85wshopware/core@6.4.6.06.4.18.1
MediumGHSA-gqw4-4w2p-838qcomposer/composer@2.1.112.2.27
MediumGHSA-52m2-vc4m-jj33twig/twig@v3.3.33.4.3
MediumGHSA-x7cr-6qr6-2hh6composer/composer@2.1.112.2.12
MediumGHSA-jm6m-4632-36hfcomposer/composer@2.1.112.2.22
MediumGHSA-25mq-v84q-4j7rguzzlehttp/guzzle@7.4.07.4.5
MediumGHSA-3vjh-xrhf-v9xhdompdf/dompdf@v1.0.22.0.0
MediumGHSA-h7vf-5wrv-9fhvsymfony/http-kernel@v5.3.105.4.20
MediumGHSA-f2wf-25xc-69c9guzzlehttp/guzzle@7.4.07.4.4
MediumGHSA-w248-ffj2-4v5qguzzlehttp/guzzle@7.4.07.4.4
MediumGHSA-47f6-5gq3-vx9ccomposer/composer@2.1.112.2.24
MediumGHSA-q559-8m2m-g699guzzlehttp/guzzle@7.4.07.4.5
MediumGHSA-cwmx-hcrq-mhc3guzzlehttp/guzzle@7.4.07.4.3
MediumALPINE-CVE-2023-5678openssl@1.1.1v-r01.1.1w-r1
MediumGHSA-8xf4-w7qw-pjjwfirebase/php-jwt@v5.4.06.0.0
MediumGHSA-9wrv-g75h-8cccshopware/core@6.4.6.06.4.10.1
MediumGHSA-7p85-w9px-jpjptwig/twig@v3.3.33.26.0
MediumGHSA-m7v2-7gxm-vc2vsymfony/monolog-bridge@v5.3.75.4.52
MediumGHSA-8r3f-844c-mc37google.golang.org/protobuf@v1.31.01.33.0
MediumGHSA-wj7q-gjg8-3cpmleague/oauth2-server@8.3.38.4.2
MediumGHSA-6j75-5wfj-gh66twig/twig@v3.3.33.11.1
MediumGHSA-3rg7-wf37-54rmsymfony/http-foundation@v5.3.105.4.50
MediumGHSA-qmp9-2xwj-m6m9shopware/core@6.4.6.06.5.7.4
MediumGHSA-wg36-wvj6-r67pcomposer/composer@2.1.112.2.27
MediumGHSA-27wp-jvhw-v4xpshopware/core@6.4.6.06.5.8.13
MediumALPINE-CVE-2023-7104sqlite@3.40.1-r03.40.1-r1
MediumALPINE-CVE-2023-46218curl@8.2.1-r08.5.0-r0
MediumGHSA-9mgx-552f-59p6tecnickcom/tcpdf@6.4.26.8.0
MediumGHSA-f9f8-rm49-7jv2composer/composer@2.1.112.2.28
MediumGHSA-7gm7-8q8v-9gf2shopware/core@6.4.6.06.4.10.1
MediumGHSA-pcw8-m77r-2528mtdowling/jmespath.php@2.6.12.9.1
MediumGHSA-2xhg-w2g5-w95xsymfony/serializer@v5.3.105.3.12
MediumGHSA-35jp-8cgg-p4wjshopware/core@6.4.6.06.5.8.13
MediumGHSA-q7rv-6hp3-vh96guzzlehttp/psr7@1.8.31.8.4
MediumGHSA-q3j3-w37x-hq2qsymfony/http-kernel@v5.3.105.3.12

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
2.0.0latest4 years ago2021.12.10-debian-10-r051431902,972

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/robjuz/shopware.svg)](https://charts.stackradar.io/charts/robjuz/shopware)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.