GUYCOLLE GmbH

← Blog

· Shopware 6 · 3 min read

Shopware security update first, EU labels due 27 September

Two dates sit close together: the security update of 25 August 2026 and the EU information requirement from 27 September 2026. If both are still open, start with security.

Shopware: Sicherheitsupdate nachholen, Labels bis 27. September Shopware

Nine vulnerabilities since 25 August

On 25.08.2026 Shopware released versions 6.7.13.1 and 6.6.10.23. The release notes for 6.6.10.23 list nine vulnerabilities. Among them a break-out from the app script sandbox with arbitrary PHP and OS code execution, host header poisoning during password reset, SQL injection risks, DNS rebinding and missing rate limiting.

Sansec published a public analysis on the same day. It describes the takeover of an administrator account followed by PHP execution on the server. The attack requires a valid sales channel key. Headless storefronts hand that key to the client during normal operation, so those setups are particularly exposed. Shopware rates the issue as high, CVSS 8.6.

Anything below 6.7.13.1 or 6.6.10.23 is unpatched. Where an immediate update is not feasible, Shopware and Sansec point to the security plugin and to restricting Store API access as an interim measure.

Two details can trip up the update itself. Entity and field names from the entities.xml of apps and plugins are now validated at install and update time. And the admin password reset falls back to APP_URL when no trusted hosts are configured, so that value must hold the real public address. With reverse proxy and multi-domain setups it is worth a check before going live.

6.7.14.0 and the EU labels

Shopware 6.7.14.0 was released on 09.09.2026. It includes native support for two new mandatory EU disclosures, across all plans including the Community Edition and without an additional extension. The basis is Implementing Regulation (EU) 2025/1960 under Directive (EU) 2024/825. It applies from 27.09.2026 to the sale of physical goods to consumers in the EU.

The legal guarantee notice affects practically every B2C product page. It is maintained under Settings, Cart settings, Checkout and can be overridden per sales channel. The text is available in all 24 official EU languages, with English as the fallback. On the order confirmation page a link is added next to the terms checkbox, pointing to the European Commission information page.

The GARAN label becomes due on top of that as soon as a manufacturer guarantee is advertised. It sits on the product detail page per product, and only duration, manufacturer and model can be edited. Design and wording of both labels are prescribed. Building your own version is therefore not an option.

Whether the feature will be backported to the 6.6 line is not confirmed in Shopware's own sources. For shops on 6.6 that remains the open planning question. Forcing a short-notice jump to 6.7 purely for the labels is hard to cost out before that is clarified.

Also in 6.7.14.0: Ratepay invoice payment via Shopware Payments, a clearer order status history, simplified language management, a new Automation menu entry and a ready-made flow for failed payments.

What to do now

The technical effort for the labels is manageable. Gathering the information takes longer. Guarantee duration, scope and whether it is free of charge should be confirmed by the manufacturers in writing, and supplier correspondence drags on for weeks. Start that today, independently of any maintenance window.

With customised themes, rework is likely. Overridden templates for the product page and checkout will not place the labels in the right spot on their own. Include the mobile view in the check.

For Swiss shops selling only to customers inside Switzerland, the regulation does not cover those sales. Anyone shipping physical goods to consumers in the EU should have the classification confirmed legally.

  • Check the patch level: anything below 6.7.13.1 or 6.6.10.23 is exposed

  • Handle the security update and the move to 6.7.14.0 in one maintenance window

  • Review apps and plugins for entity and field names, verify APP_URL

  • Obtain guarantee details from manufacturers in writing

  • Test checkout and product page templates for label rendering, mobile included

  • Plan ahead: replace PHP 8.2 before its end of life in late 2026, and MySQL 8.0

More posts

Get in touch.

Tell us what's stuck or what you want to build. You'll reach someone who knows the answer, not a switchboard.