StackRadar

shopware 2.0.0 Helm chart

robjuz

Scored 14 Sept 2026

Web publishing platform for building blogs and websites.

Version 2.0.0 4 years agodeploys tag 2021.12.10-debian-10-r0 0Artifact Hub

shopware 2.0.0 deploys 6 container images: bitnami/minio, bitnami/bitnami-shell, bitnami/elasticsearch, bitnami/mariadb and 2 more. Across the 1 measured, 239 findings5 critical, 1 high 3 on CISA KEV. The highest contribution is GHSA-x752-qjv4-c4hc in dompdf/dompdf v1.0.2, fixed in 1.2.1.

Radar Score

2,9725143190

239 findings over 1 of 6 images measured

KEV ×3 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

6 images
ImageTagVulnerabilitiesRadar Score
bitnami/minio2021.12.10-debian-10-r0unmeasured
bitnami/bitnami-shell×310-debian-10-r273unmeasured
bitnami/elasticsearch×37.16.0-debian-10-r0unmeasured
bitnami/mariadb10.5.13-debian-10-r0unmeasured
bitnami/redis6.2.6-debian-10-r53unmeasured
shyim/shopware×36.4.6.051431902,972

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

239 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-f8q6-3g5w-jjr6shopware/core@6.4.6.06.6.10.18
LowALPINE-CVE-2023-43785libx11@1.8-r11.8.7-r0
LowGHSA-97m3-52wr-xvv2phenx/php-svg-lib@0.3.40.5.2
LowGHSA-4p8j-vhjm-6pvwtecnickcom/tcpdf@6.4.26.8.0
LowGHSA-7fxw-r6jv-74c8twig/twig@v3.3.33.26.0
LowGO-2024-2963stdlib@go1.20.71.21.12
LowGHSA-r64m-qchj-hrjpshopware/core@6.4.6.06.4.6.1
LowGHSA-x6g4-fwcc-jj8wsymfony/dom-crawler@v5.3.75.4.52
LowGHSA-qx95-cwh6-9mvqtecnickcom/tcpdf@6.4.26.8.0
LowGHSA-cx96-42px-69fmdompdf/dompdf@v1.0.23.1.6
LowGHSA-v5mv-p594-2x33guzzlehttp/guzzle@7.4.07.15.2
LowGO-2023-2382stdlib@go1.20.71.20.12
LowALPINE-CVE-2023-43786libx11@1.8-r11.8.7-r0
LowGHSA-j8qw-6jw8-r297dompdf/dompdf@v1.0.23.1.6
LowGO-2024-2599stdlib@go1.20.71.21.8
LowGHSA-5297-wrrp-rcj7shopware/core@6.4.6.06.5.8.8
LowGO-2024-3106stdlib@go1.20.71.22.7
LowGHSA-5v5v-ww74-355vtwig/twig@v3.3.33.27.0
LowGO-2024-2600stdlib@go1.20.71.21.8
LowALPINE-CVE-2023-42366busybox@1.35.0-r171.35.0-r18
LowGHSA-h8vq-8gpg-mhcgtwig/twig@v3.3.33.27.0
LowGHSA-6w82-v552-wjw2shopware/storefront@6.4.6.06.6.10.10
LowGO-2024-2609stdlib@go1.20.71.21.8
LowGO-2024-3107stdlib@go1.20.71.22.7
LowGHSA-hhcq-ph6w-494gshopware/core@6.4.6.06.5.8.13
LowGHSA-8x9c-rmqh-456ctwig/twig@v3.3.33.27.0
LowGHSA-59pp-r3rg-353gcomposer/composer@2.1.112.2.26
LowGO-2023-2041stdlib@go1.20.71.20.8
LowGHSA-jp6h-mxhx-pgqhshopware/storefront@6.4.6.06.4.8.2
LowGO-2023-2043stdlib@go1.20.71.20.8
LowGHSA-hh7j-6x3q-f52hshopware/core@6.4.6.06.5.8.18
LowGHSA-72xp-p242-47p9symfony/routing@v5.3.75.4.52
LowGO-2023-2186stdlib@go1.20.71.20.11
LowGHSA-xvhc-gm7j-mhmcshopware/core@6.4.6.06.6.10.18
LowGHSA-499r-g7pc-vmp9composer/composer@2.1.112.2.29
LowGO-2024-3105stdlib@go1.20.71.22.7
LowGHSA-r39x-jcww-82v6symfony/process@v5.3.75.4.51
LowGO-2026-4981stdlib@go1.20.71.25.10
LowGO-2025-3563stdlib@go1.20.71.23.8
LowGHSA-h95v-h523-3mw8guzzlehttp/guzzle@7.4.07.15.1
LowGO-2026-4977stdlib@go1.20.71.25.10
LowGO-2024-2610stdlib@go1.20.71.21.8
LowGO-2026-4986stdlib@go1.20.71.25.10
LowGO-2026-4918stdlib@go1.20.71.25.10
LowGO-2026-4337stdlib@go1.20.71.24.13
LowGHSA-46h7-vj7x-fxg2shopware/core@6.4.6.06.4.18.1
LowGHSA-3867-jc5c-66qfshopware/core@6.4.6.06.5.7.4
LowGHSA-wm3w-8rrp-j577guzzlehttp/guzzle@7.4.07.15.1
LowGO-2026-4601stdlib@go1.20.71.25.8
LowGHSA-27qh-8cxx-2cr5aws/aws-sdk-php@3.198.83.371.4

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
2.0.0latest4 years ago2021.12.10-debian-10-r051431902,972

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/robjuz/shopware.svg)](https://charts.stackradar.io/charts/robjuz/shopware)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.