CVE-2025-32378 Details
Description
Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolicited newsletter sign-ups without confirmation. Default settings are Newsletter: Double Opt-in set to active, Newsletter: Double opt-in for registered customers set to disabled, and Log-in & sign-up: Double opt-in on sign-up set to disabled. With these settings, anyone can register an account on the shop using any e-mail-address and then check the check-box in the account page to sign up for the newsletter. The recipient will receive two mails confirming registering and signing up for the newsletter, no confirmation link needed to be clicked for either. In the backend the recipient is set to “instantly active”. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17.
A vulnerability in Shopware's default double-opt-in newsletter settings allows for mass unsolicited sign-ups without confirmation. This issue affects Shopware versions prior to 6.5.8.17 and versions 6.6.0.0 through 6.6.10.2, as well as 6.7.0.0-rc1. With the default settings, anyone can register an account using any email address and sign up for the newsletter without needing to click a confirmation link. The recipient receives two confirmation emails, and their subscription is activated immediately in the backend.
Users can update to Shopware versions 6.5.8.17, 6.6.10.3, or 6.7.0.0-rc2 to address this vulnerability. For older versions of 6.4, corresponding security measures are available via a plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/shopware/shopware/security/advisories/GHSA-4h9w-7vfp-px8m | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-799 | Improper Control of Interaction Frequency | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| shopware shopware | < 6.5.8.17 >= 6.6.0.0, < 6.6.10.3 6.7.0.0 rc1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2025 | Initial Analysis | [email protected] |
| Apr 9, 2025 | New CVE Received | [email protected] |