{"id":"CVE-2025-7954","aliases":["GHSA-27gv-mg7w-mm34"],"url":"https://o3.security/vulnerability/CVE-2025-7954","summary":"Race Condition in Shopware Voucher Submission","details":"A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.","published":"2025-08-06T07:16:09.712Z","modified":"2026-07-15T01:49:12.134507567Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"shopware/platform","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"http://seclists.org/fulldisclosure/2025/Aug/17"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7954.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-7954"},{"type":"REPORT","url":"https://github.com/shopware/shopware/issues/11245"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:12.134507567Z"}}