Skip to content

Weekly roundup

Open-source business platforms, week 38 2026: critical ERPNext and Shopware flaws lead 49 fixes

Critical 9.6 Vendor: Open-source business platforms 49 advisories in scope Published

Open-source business platforms, week 38 of 2026: 49 CVEs in scope, 3 critical, 20 high, none exploited or in CISA KEV. Critical ERPNext SQL injection and stored XSS plus a Shopware webhook permission flaw need prompt patching.

The release at a glance

During the week of 14–20 September 2026, maintainers of open-source business platforms published advisories covering 49 CVEs in scope for our readers. The release is dominated by ERPNext (28), followed by WordPress (11), Shopware (5), Server (3), Frappe (1) and Frappe Framework (1). Severity breakdown: 3 critical, 20 high, 19 medium, 2 low and 5 unscored. No CVE in this release is marked exploited, and none appears in CISA KEV. The critical entries are in ERPNext and Shopware, so readers running either should treat this as a priority update.

What matters most

Three flaws in ERPNext and three in Shopware warrant immediate review.

In ERPNext, GHSA-v38v-9h2p-hr8v is a critical SQL injection in some endpoints; any authenticated user, even without assigned roles, could read other users' sensitive information and escalate to a privileged account. It is fixed in ERPNext 15.121.0 and 16.34.0. GHSA-rv4r-c8v3-3hrc is a critical stored cross-site scripting flaw in a public-facing booking page, allowing an unauthenticated attacker to execute script in a privileged user's session and act as that user; it is fixed in ERPNext 15.119.1 and 16.32.0. GHSA-f99r-gp2w-xghj is a high stored cross-site scripting flaw in a report view; it is fixed in ERPNext 15.120.0 and 16.33.0. Two further high-severity ERPNext missing-validation flaws are worth noting: GHSA-wp9w-rxmg-6pfj allows users to modify data beyond their permitted role and is fixed in 15.121.0 and 16.34.0, while GHSA-wwgm-3pv3-gmqh allows authenticated users to read party records beyond their permitted role and is fixed in 15.120.0 and 16.23.0.

In Shopware, GHSA-r432-q883-wgvf is a critical webhook permission issue: under certain configurations, a user or integration with webhook creation privileges could receive event data beyond assigned permissions, including customer, order, business-process or email-related data and potentially account-recovery information. It is fixed in Shopware 6.6.10.25 and 6.7.14.1. GHSA-2qxr-vvj4-5934 is a high SQL injection through Store API aggregation handling when running on PHP before 8.4 with PDO MySQL emulated prepares enabled; an unauthenticated Store API client may read arbitrary data from the underlying database. It is fixed in Shopware 6.6.10.25 and 6.7.14.1. GHSA-8xfc-pww7-3rm5 is a high privilege escalation in Shopware Administration: a user with the user_change_me permission could promote their account to administrator. It is fixed in Shopware 6.6.10.25 and 6.7.14.1.

Patch in this order

  1. Patch ERPNext first. Apply ERPNext 15.121.0 / 16.34.0 to close the critical SQL injection, GHSA-v38v-9h2p-hr8v, and the high missing-validation flaws in the same branch. Apply the earlier stored cross-site scripting fix in 15.119.1 / 16.32.0 for GHSA-rv4r-c8v3-3hrc if you have not already.
  2. Patch Shopware next. Upgrade to Shopware 6.6.10.25 or 6.7.14.1, which closes the critical webhook permission issue, the unauthenticated Store API SQL injection and the administration privilege escalation.
  3. Then update the remaining ERPNext advisories to the fixed versions listed in the table, including 15.121.3 / 16.35.0 for GHSA-cgjf-xw8x-qjjc and 15.120.0 / 16.23.0 for GHSA-wwgm-3pv3-gmqh, so all missing-validation and stored cross-site scripting flaws are covered.
  4. Review WordPress, Server, Frappe and Frappe Framework items after the ERPNext and Shopware updates. None are exploited in this release, and none appear in CISA KEV.
  5. For the Shopware SQL injection and privilege escalation, use the vendor workarounds until patching: upgrade to PHP 8.4 or later or disable PDO MySQL emulated prepares, and restrict user_change_me permission or administration access.

Beyond the patch

Next month this is manageable if you map which of these platforms you run and how quickly their maintainers fix high-impact flaws. Our Implementation & Assessment Services include penetration testing and hardening that find injection and authentication weaknesses like the ERPNext SQL injection and stored cross-site scripting flaws, while Virtual CISO Services (vCISO) can help you identify internet-exposed endpoints like the unauthenticated Shopware Store API issue before an update lands.

Every advisory in this release

IDProductSeverity
GHSA-v38v-9h2p-hr8vERPNextCritical 9.6Advisory →
GHSA-r432-q883-wgvfShopwareCritical 9.6Advisory →
GHSA-rv4r-c8v3-3hrcERPNextCritical 9.3Advisory →
GHSA-f99r-gp2w-xghjERPNextHigh 8.7Advisory →
GHSA-734c-hv9r-mg2cERPNextHigh 8.7Advisory →
GHSA-2qxr-vvj4-5934ShopwareHigh 8.6Advisory →
GHSA-wp9w-rxmg-6pfjERPNextHigh 8.5Advisory →
GHSA-cgjf-xw8x-qjjcERPNextHigh 8.5Advisory →
GHSA-vr45-2p9x-3vjcERPNextHigh 8.5Advisory →
GHSA-8xfc-pww7-3rm5ShopwareHigh 8.1Advisory →
GHSA-wwgm-3pv3-gmqhERPNextHigh 7.7Advisory →
GHSA-jfwr-g9v2-57c9ERPNextHigh 7.7
GHSA-jp5q-723q-g826ERPNextHigh 7.7
GHSA-5wpj-6rvp-9ff7ERPNextHigh 7.7Advisory →
GHSA-q6qw-66cm-f9wjERPNextHigh 7.7
GHSA-mp29-fjc5-h86pERPNextHigh 7.7
GHSA-726x-68g4-fj9vERPNextHigh 7.7Advisory →
GHSA-cgxw-2996-9vj3ERPNextHigh 7.7
GHSA-xp5c-86f4-7ppfERPNextHigh 7.7
GHSA-pg3r-7236-pg74ERPNextHigh 7.7
GHSA-qcff-6669-j3gjERPNextHigh 7.7
GHSA-vg6r-89q7-wh34ERPNextHigh 7.7
CVE-2026-94113ERPNextHigh 7.1
GHSA-h787-3x6w-8x4mERPNextMedium 6.8
CVE-2026-82985ServerMedium 6.5
GHSA-p589-2ff8-3wfwShopwareMedium 6.5Advisory →
GHSA-33wf-p63q-w25fWordPressMedium 6.5
GHSA-49wp-r82c-j825ERPNextMedium 6.4
GHSA-794x-fhm7-58j7ERPNextMedium 6.4
CVE-2026-77164ServerMedium 6.2
CVE-2023-51769FrappeMedium 6.1
GHSA-mch6-932v-3cm8ShopwareMedium 5.3Advisory →
GHSA-cjfg-q57r-mq45WordPressMedium 5.3
GHSA-5qf7-2r5p-ppj8WordPressMedium 5.3
GHSA-76jg-r2qr-v77fWordPressMedium 5.3
GHSA-7j2w-hg27-8g3qERPNextMedium 5.0
GHSA-pr7v-95jp-gwwvERPNextMedium 4.3
GHSA-2r76-j6jj-jj56ERPNextMedium 4.3
GHSA-9vph-hqmm-g7hqERPNextMedium 4.3
GHSA-p4jx-mqwq-66cjERPNextMedium 4.3
Show all 49
IDProductSeverity
GHSA-32m5-wc28-ghrrWordPressMedium 4.3
GHSA-w57f-v787-qhpfWordPressMedium 4.3
CVE-2026-68493ServerLow 3.1
GHSA-rmpv-w5v9-rqh5WordPressLow 1.8
GHSA-8v98-cfpm-9p67Frappe FrameworkNot scored
GHSA-f522-h982-63mgWordPressNot scored
GHSA-qg7r-fjh2-wvx8WordPressNot scored
GHSA-xhp5-863h-rhfrWordPressNot scored
GHSA-mgvw-845h-9qgqWordPressNot scored

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them. Entries marked GHSA have no CVE: their source is the security advisory the maintainers published in their official GitHub repository.

Written with AI assistance from the sources above and checked automatically against them before publication.