StackRadar

shyim/shopware:6.4.6.0 container image

Docker Hub

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of shyim/shopware

shyim/shopware:6.4.6.0 resolved to a951c0e6b836, scanned 14 Sept 2026: 239 findings, 5 critical, 3 on KEV; deployed by 1 chart, among them shopware.

Radar Score

2,9725143190

239 findings on digest a951c0e6b836 · scanned 14 Sept 2026

KEV ×3 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
6.4.6.0resolves toa951c0e6b8361 chart5 days ago51431902,972

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Medium findings

43 distinct on this digest

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

Findings for digest a951c0e6b836 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
MediumGO-2024-2687stdlib@go1.20.71.21.9
MediumGHSA-5mv2-rx3q-4w2vtwig/twig@v3.3.33.3.8
MediumGHSA-8g35-7rmw-7f59shopware/core@6.4.6.06.5.8.18
MediumGHSA-3cw5-7cxw-v5qgdompdf/dompdf@v1.0.22.0.2
MediumGHSA-v9qv-c7wm-wgmfcomposer/composer@2.1.112.2.24
MediumGHSA-6x28-7h8c-chx4dompdf/dompdf@v1.0.22.0.1
MediumGHSA-7v2v-9rm4-7m8fshopware/core@6.4.6.06.4.20.1
MediumGHSA-577p-7j7h-2jgfdompdf/dompdf@v1.0.22.0.0
MediumGHSA-93cw-f5jj-x85wshopware/core@6.4.6.06.4.18.1
MediumGHSA-gqw4-4w2p-838qcomposer/composer@2.1.112.2.27
MediumGHSA-52m2-vc4m-jj33twig/twig@v3.3.33.4.3
MediumGHSA-x7cr-6qr6-2hh6composer/composer@2.1.112.2.12
MediumGHSA-jm6m-4632-36hfcomposer/composer@2.1.112.2.22
MediumGHSA-25mq-v84q-4j7rguzzlehttp/guzzle@7.4.07.4.5
MediumGHSA-3vjh-xrhf-v9xhdompdf/dompdf@v1.0.22.0.0
MediumGHSA-h7vf-5wrv-9fhvsymfony/http-kernel@v5.3.105.4.20
MediumGHSA-f2wf-25xc-69c9guzzlehttp/guzzle@7.4.07.4.4
MediumGHSA-w248-ffj2-4v5qguzzlehttp/guzzle@7.4.07.4.4
MediumGHSA-47f6-5gq3-vx9ccomposer/composer@2.1.112.2.24
MediumGHSA-q559-8m2m-g699guzzlehttp/guzzle@7.4.07.4.5
MediumGHSA-cwmx-hcrq-mhc3guzzlehttp/guzzle@7.4.07.4.3
MediumALPINE-CVE-2023-5678openssl@1.1.1v-r01.1.1w-r1
MediumGHSA-8xf4-w7qw-pjjwfirebase/php-jwt@v5.4.06.0.0
MediumGHSA-9wrv-g75h-8cccshopware/core@6.4.6.06.4.10.1
MediumGHSA-7p85-w9px-jpjptwig/twig@v3.3.33.26.0
MediumGHSA-m7v2-7gxm-vc2vsymfony/monolog-bridge@v5.3.75.4.52
MediumGHSA-8r3f-844c-mc37google.golang.org/protobuf@v1.31.01.33.0
MediumGHSA-wj7q-gjg8-3cpmleague/oauth2-server@8.3.38.4.2
MediumGHSA-6j75-5wfj-gh66twig/twig@v3.3.33.11.1
MediumGHSA-3rg7-wf37-54rmsymfony/http-foundation@v5.3.105.4.50
MediumGHSA-qmp9-2xwj-m6m9shopware/core@6.4.6.06.5.7.4
MediumGHSA-wg36-wvj6-r67pcomposer/composer@2.1.112.2.27
MediumGHSA-27wp-jvhw-v4xpshopware/core@6.4.6.06.5.8.13
MediumALPINE-CVE-2023-7104sqlite@3.40.1-r03.40.1-r1
MediumALPINE-CVE-2023-46218curl@8.2.1-r08.5.0-r0
MediumGHSA-9mgx-552f-59p6tecnickcom/tcpdf@6.4.26.8.0
MediumGHSA-f9f8-rm49-7jv2composer/composer@2.1.112.2.28
MediumGHSA-7gm7-8q8v-9gf2shopware/core@6.4.6.06.4.10.1
MediumGHSA-pcw8-m77r-2528mtdowling/jmespath.php@2.6.12.9.1
MediumGHSA-2xhg-w2g5-w95xsymfony/serializer@v5.3.105.3.12
MediumGHSA-35jp-8cgg-p4wjshopware/core@6.4.6.06.5.8.13
MediumGHSA-q7rv-6hp3-vh96guzzlehttp/psr7@1.8.31.8.4
MediumGHSA-q3j3-w37x-hq2qsymfony/http-kernel@v5.3.105.3.12

Used by

1 chart
ChartVersionTagContainers
shopwarerobjuz2.0.06.4.6.03

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.