CVE-2025-7954: Race Condition in Shopware Voucher Submission
Published Aug 6, 2025
·Updated
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
Affected Software
3 affected components
Shopware Shopware
composer/shopware/platform<=6.6.10.4
Shopware Shopware>=6.6.0.0<6.7.2.0
Event History
Aug 6, 2025
CVE Published
via MITRE·07:16 AM
Data Sourced
via MITRE·07:16 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
Affected Software
Advisory Published
via GitHub·09:30 AM
Data Sourced
via GitHub·09:30 AM
DescriptionWeaknessAffected Software
Jun 16, 58473
Event
via NVD·09:23 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-7954?
CVE-2025-7954 is classified as a high severity vulnerability due to its potential to allow attackers to bypass voucher restrictions.
2
How do I fix CVE-2025-7954?
To fix CVE-2025-7954, update your Shopware installation to the latest version available that addresses this vulnerability.
3
What versions of Shopware are affected by CVE-2025-7954?
CVE-2025-7954 affects Shopware v6.6.10.4 and possibly earlier versions.
4
What type of vulnerability is CVE-2025-7954?
CVE-2025-7954 is a race condition vulnerability found in Shopware's voucher system.
5
What impact does CVE-2025-7954 have on Shopware users?
CVE-2025-7954 allows attackers to exceed usage limitations on vouchers, potentially leading to financial loss for users.