StackRadar

shopware Helm chart

robjuz

Scored 14 Sept 2026

Web publishing platform for building blogs and websites.

Latest 2.0.0 4 years agodeploys tag 2021.12.10-debian-10-r0 0Artifact Hub

shopware 2.0.0 deploys 6 container images: bitnami/minio, bitnami/bitnami-shell, bitnami/elasticsearch, bitnami/mariadb and 2 more. Across the 1 measured, 239 findings5 critical, 1 high 3 on CISA KEV. The highest contribution is GHSA-x752-qjv4-c4hc in dompdf/dompdf v1.0.2, fixed in 1.2.1.

Radar Score

2,9725143190

239 findings over 1 of 6 images measured

KEV ×3 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

6 images
ImageTagVulnerabilitiesRadar Score
bitnami/minio2021.12.10-debian-10-r0unmeasured
bitnami/bitnami-shell×310-debian-10-r273unmeasured
bitnami/elasticsearch×37.16.0-debian-10-r0unmeasured
bitnami/mariadb10.5.13-debian-10-r0unmeasured
bitnami/redis6.2.6-debian-10-r53unmeasured
shyim/shopware×36.4.6.051431902,972

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

239 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2023-38546curl@8.2.1-r08.4.0-r0
LowGHSA-f3qr-qr4x-j273phenx/php-svg-lib@0.3.40.5.2
LowGHSA-6wrh-279j-6hvwshopware/storefront@6.4.6.06.4.8.2
LowGHSA-6wrh-279j-6hvwshopware/core@6.4.6.06.4.8.2
LowGHSA-w95c-7994-ghprtecnickcom/tcpdf@6.4.26.8.0
LowGHSA-qq5c-677p-737qsymfony/process@v5.3.75.4.46
LowGO-2023-2102stdlib@go1.20.71.20.10
LowGHSA-83vp-6jqg-6cmrshopware/core@6.4.6.06.4.8.2
LowGHSA-529h-vh3j-85hqtwig/twig@v3.3.33.27.0
LowGHSA-p6w9-r443-r752shopware/core@6.4.6.06.5.8.13
LowGHSA-4qpc-3hr4-r2p4symfony/yaml@v5.3.65.4.52
LowGHSA-9frc-8383-795msymfony/yaml@v5.3.65.4.52
LowGHSA-3qx2-6f78-w2j2dompdf/dompdf@v1.0.22.0.4
LowGHSA-qpmx-3rfj-7rhvsymfony/mime@v5.3.85.4.52
LowGHSA-c2p3-7m5p-cv8xsymfony/yaml@v5.3.65.4.52
LowALPINE-CVE-2023-43787libx11@1.8-r11.8.7-r0
LowGHSA-557v-xcg6-rm5maws/aws-sdk-php@3.198.83.288.1
LowGHSA-rmv2-8jjc-23xwtecnickcom/tcpdf@6.4.26.7.6
LowGHSA-7c6p-848j-wh5hcomposer/composer@2.1.112.2.23
LowGHSA-952p-fqcp-g8pcshopware/core@6.4.6.06.4.8.1
LowGHSA-952p-fqcp-g8pcshopware/storefront@6.4.6.06.4.8.1
LowGHSA-c4p7-rwrg-pf6pshopware/core@6.4.6.06.6.10.15
LowGHSA-f5gf-2cj8-52g2dompdf/dompdf@v1.0.23.1.6
LowGHSA-rvx4-ffvw-m9q3composer/composer@2.1.112.2.30
LowGHSA-5qj8-6xxj-hp9hdompdf/dompdf@v1.0.22.0.0
LowGHSA-wxmh-65f7-jcvwguzzlehttp/psr7@1.8.31.9.1
LowGHSA-35wc-cvqg-78fptwig/intl-extra@v3.3.03.26.0
LowGHSA-2xf4-cg6j-vhgqsymfony/polyfill-intl-idn@v1.23.01.38.1
LowGO-2023-2185stdlib@go1.20.71.20.11
LowGHSA-mx3p-fhpw-x6rvtecnickcom/tcpdf@6.4.26.7.5
LowGHSA-cgfj-hj93-rmh2shopware/core@6.4.6.06.5.8.17
LowGHSA-pr2w-4gpj-cpq4twig/twig@v3.3.33.26.0
LowALPINE-CVE-2023-46219curl@8.2.1-r08.5.0-r0
LowGHSA-7vvp-j573-5584shopware/core@6.4.6.06.6.10.15
LowGHSA-vvj3-c3rp-c85pphpunit/phpunit@9.5.99.6.33
LowGHSA-8r6h-m72v-38fgshopware/core@6.4.6.06.4.18.1
LowGHSA-6qh9-h6wf-jgqcsymfony/cache@v5.3.105.4.52
LowGHSA-q847-2q57-wmr3symfony/twig-bridge@v5.3.75.4.31
LowGHSA-pf6p-25r2-fx45dompdf/dompdf@v1.0.22.0.0
LowGHSA-8v9p-g828-v98fshopware/core@6.4.6.06.6.10.18
LowGHSA-vqc8-7275-q272symfony/mime@v5.3.85.4.52
LowGO-2026-4341stdlib@go1.20.71.24.12
LowGHSA-g9wg-98c2-qv3vtecnickcom/tcpdf@6.4.26.7.4
LowGHSA-ff5x-7qg5-vwf2phenx/php-svg-lib@0.3.40.5.1
LowGHSA-gv8p-48fr-4fxgshopware/core@6.4.6.06.6.10.18
LowGHSA-v39m-97p8-gqg7shopware/core@6.4.6.06.6.10.18
LowGHSA-8hg6-c449-896mdompdf/dompdf@v1.0.23.1.6
LowGO-2024-2887stdlib@go1.20.71.21.11
LowALPINE-CVE-2025-26519musl@1.2.3-r31.2.3-r4
LowGHSA-h5x3-xfc9-m39hsymfony/routing@v5.3.75.4.53

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
2.0.0latest4 years ago2021.12.10-debian-10-r051431902,972

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/robjuz/shopware.svg)](https://charts.stackradar.io/charts/robjuz/shopware)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.