Medium severity4.3NVD Advisory· Published Jan 17, 2023· Updated Jun 17, 2026
CVE-2023-22734
CVE-2023-22734
Description
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly, and it was possible to skip the complete double opt in process. As a result operators may have inconsistencies in their newsletter systems. This problem has been fixed with version 6.4.18.1. Users are advised to upgrade. Users unable to upgrade may find security measures are available via a plugin for major versions 6.1, 6.2, and 6.3. Users may also disable newsletter registration completely.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shopware/platformPackagist | < 6.4.18.1 | 6.4.18.1 |
shopware/corePackagist | < 6.4.18.1 | 6.4.18.1 |
Affected products
4- shopware/platformv5Range: < 6.4.18.1
- ghsa-coords2 versions
< 6.4.18.1+ 1 more
- (no CPE)range: < 6.4.18.1
- (no CPE)range: < 6.4.18.1
Patches
Vulnerability mechanics
References
5- docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023nvdPatchVendor AdvisoryWEB
- github.com/shopware/platform/commit/f5a95ee2bcf1e546878450963ef1d9886e59a620nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-46h7-vj7x-fxg2ghsaADVISORY
- github.com/shopware/platform/security/advisories/GHSA-46h7-vj7x-fxg2nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-22734ghsaADVISORY
News mentions
0No linked articles in our index yet.