Weekly roundup
Open-source business platforms, week 38 2026: critical ERPNext and Shopware flaws lead 49 fixes
Open-source business platforms, week 38 of 2026: 49 CVEs in scope, 3 critical, 20 high, none exploited or in CISA KEV. Critical ERPNext SQL injection and stored XSS plus a Shopware webhook permission flaw need prompt patching.
The release at a glance
During the week of 14–20 September 2026, maintainers of open-source business platforms published advisories covering 49 CVEs in scope for our readers. The release is dominated by ERPNext (28), followed by WordPress (11), Shopware (5), Server (3), Frappe (1) and Frappe Framework (1). Severity breakdown: 3 critical, 20 high, 19 medium, 2 low and 5 unscored. No CVE in this release is marked exploited, and none appears in CISA KEV. The critical entries are in ERPNext and Shopware, so readers running either should treat this as a priority update.
What matters most
Three flaws in ERPNext and three in Shopware warrant immediate review.
In ERPNext, GHSA-v38v-9h2p-hr8v is a critical SQL injection in some endpoints; any authenticated user, even without assigned roles, could read other users' sensitive information and escalate to a privileged account. It is fixed in ERPNext 15.121.0 and 16.34.0. GHSA-rv4r-c8v3-3hrc is a critical stored cross-site scripting flaw in a public-facing booking page, allowing an unauthenticated attacker to execute script in a privileged user's session and act as that user; it is fixed in ERPNext 15.119.1 and 16.32.0. GHSA-f99r-gp2w-xghj is a high stored cross-site scripting flaw in a report view; it is fixed in ERPNext 15.120.0 and 16.33.0. Two further high-severity ERPNext missing-validation flaws are worth noting: GHSA-wp9w-rxmg-6pfj allows users to modify data beyond their permitted role and is fixed in 15.121.0 and 16.34.0, while GHSA-wwgm-3pv3-gmqh allows authenticated users to read party records beyond their permitted role and is fixed in 15.120.0 and 16.23.0.
In Shopware, GHSA-r432-q883-wgvf is a critical webhook permission issue: under certain configurations, a user or integration with webhook creation privileges could receive event data beyond assigned permissions, including customer, order, business-process or email-related data and potentially account-recovery information. It is fixed in Shopware 6.6.10.25 and 6.7.14.1. GHSA-2qxr-vvj4-5934 is a high SQL injection through Store API aggregation handling when running on PHP before 8.4 with PDO MySQL emulated prepares enabled; an unauthenticated Store API client may read arbitrary data from the underlying database. It is fixed in Shopware 6.6.10.25 and 6.7.14.1. GHSA-8xfc-pww7-3rm5 is a high privilege escalation in Shopware Administration: a user with the user_change_me permission could promote their account to administrator. It is fixed in Shopware 6.6.10.25 and 6.7.14.1.
Patch in this order
- Patch ERPNext first. Apply ERPNext 15.121.0 / 16.34.0 to close the critical SQL injection, GHSA-v38v-9h2p-hr8v, and the high missing-validation flaws in the same branch. Apply the earlier stored cross-site scripting fix in 15.119.1 / 16.32.0 for GHSA-rv4r-c8v3-3hrc if you have not already.
- Patch Shopware next. Upgrade to Shopware 6.6.10.25 or 6.7.14.1, which closes the critical webhook permission issue, the unauthenticated Store API SQL injection and the administration privilege escalation.
- Then update the remaining ERPNext advisories to the fixed versions listed in the table, including 15.121.3 / 16.35.0 for GHSA-cgjf-xw8x-qjjc and 15.120.0 / 16.23.0 for GHSA-wwgm-3pv3-gmqh, so all missing-validation and stored cross-site scripting flaws are covered.
- Review WordPress, Server, Frappe and Frappe Framework items after the ERPNext and Shopware updates. None are exploited in this release, and none appear in CISA KEV.
- For the Shopware SQL injection and privilege escalation, use the vendor workarounds until patching: upgrade to PHP 8.4 or later or disable PDO MySQL emulated prepares, and restrict user_change_me permission or administration access.
Beyond the patch
Next month this is manageable if you map which of these platforms you run and how quickly their maintainers fix high-impact flaws. Our Implementation & Assessment Services include penetration testing and hardening that find injection and authentication weaknesses like the ERPNext SQL injection and stored cross-site scripting flaws, while Virtual CISO Services (vCISO) can help you identify internet-exposed endpoints like the unauthenticated Shopware Store API issue before an update lands.
Every advisory in this release
| ID | Product | Severity | |
|---|---|---|---|
| GHSA-v38v-9h2p-hr8v | ERPNext | Critical 9.6 | Advisory → |
| GHSA-r432-q883-wgvf | Shopware | Critical 9.6 | Advisory → |
| GHSA-rv4r-c8v3-3hrc | ERPNext | Critical 9.3 | Advisory → |
| GHSA-f99r-gp2w-xghj | ERPNext | High 8.7 | Advisory → |
| GHSA-734c-hv9r-mg2c | ERPNext | High 8.7 | Advisory → |
| GHSA-2qxr-vvj4-5934 | Shopware | High 8.6 | Advisory → |
| GHSA-wp9w-rxmg-6pfj | ERPNext | High 8.5 | Advisory → |
| GHSA-cgjf-xw8x-qjjc | ERPNext | High 8.5 | Advisory → |
| GHSA-vr45-2p9x-3vjc | ERPNext | High 8.5 | Advisory → |
| GHSA-8xfc-pww7-3rm5 | Shopware | High 8.1 | Advisory → |
| GHSA-wwgm-3pv3-gmqh | ERPNext | High 7.7 | Advisory → |
| GHSA-jfwr-g9v2-57c9 | ERPNext | High 7.7 | |
| GHSA-jp5q-723q-g826 | ERPNext | High 7.7 | |
| GHSA-5wpj-6rvp-9ff7 | ERPNext | High 7.7 | Advisory → |
| GHSA-q6qw-66cm-f9wj | ERPNext | High 7.7 | |
| GHSA-mp29-fjc5-h86p | ERPNext | High 7.7 | |
| GHSA-726x-68g4-fj9v | ERPNext | High 7.7 | Advisory → |
| GHSA-cgxw-2996-9vj3 | ERPNext | High 7.7 | |
| GHSA-xp5c-86f4-7ppf | ERPNext | High 7.7 | |
| GHSA-pg3r-7236-pg74 | ERPNext | High 7.7 | |
| GHSA-qcff-6669-j3gj | ERPNext | High 7.7 | |
| GHSA-vg6r-89q7-wh34 | ERPNext | High 7.7 | |
| CVE-2026-94113 | ERPNext | High 7.1 | |
| GHSA-h787-3x6w-8x4m | ERPNext | Medium 6.8 | |
| CVE-2026-82985 | Server | Medium 6.5 | |
| GHSA-p589-2ff8-3wfw | Shopware | Medium 6.5 | Advisory → |
| GHSA-33wf-p63q-w25f | WordPress | Medium 6.5 | |
| GHSA-49wp-r82c-j825 | ERPNext | Medium 6.4 | |
| GHSA-794x-fhm7-58j7 | ERPNext | Medium 6.4 | |
| CVE-2026-77164 | Server | Medium 6.2 | |
| CVE-2023-51769 | Frappe | Medium 6.1 | |
| GHSA-mch6-932v-3cm8 | Shopware | Medium 5.3 | Advisory → |
| GHSA-cjfg-q57r-mq45 | WordPress | Medium 5.3 | |
| GHSA-5qf7-2r5p-ppj8 | WordPress | Medium 5.3 | |
| GHSA-76jg-r2qr-v77f | WordPress | Medium 5.3 | |
| GHSA-7j2w-hg27-8g3q | ERPNext | Medium 5.0 | |
| GHSA-pr7v-95jp-gwwv | ERPNext | Medium 4.3 | |
| GHSA-2r76-j6jj-jj56 | ERPNext | Medium 4.3 | |
| GHSA-9vph-hqmm-g7hq | ERPNext | Medium 4.3 | |
| GHSA-p4jx-mqwq-66cj | ERPNext | Medium 4.3 |
Show all 49
| ID | Product | Severity | |
|---|---|---|---|
| GHSA-32m5-wc28-ghrr | WordPress | Medium 4.3 | |
| GHSA-w57f-v787-qhpf | WordPress | Medium 4.3 | |
| CVE-2026-68493 | Server | Low 3.1 | |
| GHSA-rmpv-w5v9-rqh5 | WordPress | Low 1.8 | |
| GHSA-8v98-cfpm-9p67 | Frappe Framework | Not scored | |
| GHSA-f522-h982-63mg | WordPress | Not scored | |
| GHSA-qg7r-fjh2-wvx8 | WordPress | Not scored | |
| GHSA-xhp5-863h-rhfr | WordPress | Not scored | |
| GHSA-mgvw-845h-9qgq | WordPress | Not scored |
References
Vendor advisory
- Possibility of SQL injection due to missing validation
- Webhook permission can bypass event ACLs and expose sensitive data
- Account takeover via stored cross-site scripting
- Stored cross-site scripting due to missing validation
- Stored cross-site scripting due to missing validation
- SQL injection in Store API aggregation handling on PHP < 8.4
- Unauthorised status modification due to missing validation
- Unauthorised modification of data due to missing validation
GHSA
- GHSA-v38v-9h2p-hr8v — GitHub
- GHSA-r432-q883-wgvf — GitHub
- GHSA-rv4r-c8v3-3hrc — GitHub
- GHSA-f99r-gp2w-xghj — GitHub
- GHSA-734c-hv9r-mg2c — GitHub
- GHSA-2qxr-vvj4-5934 — GitHub
- GHSA-wp9w-rxmg-6pfj — GitHub
- GHSA-cgjf-xw8x-qjjc — GitHub
- GHSA-vr45-2p9x-3vjc — GitHub
- GHSA-8xfc-pww7-3rm5 — GitHub
- GHSA-wwgm-3pv3-gmqh — GitHub
- GHSA-jfwr-g9v2-57c9 — GitHub