CVE-2025-7954 Details
Description
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
A race condition vulnerability has been identified in Shopware's voucher system in versions 6.6.10.4, 6.6.x, and 6.7.x. This vulnerability allows attackers to bypass intended voucher restrictions and exceed usage limitations. The issue arises because the validation of voucher codes is not an atomic operation, enabling vouchers to be used in multiple simultaneous checkouts. Exploitation could lead to one-time vouchers being used beyond their intended limit.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/shopware/shopware/issues/11245 | CISA-ADP | ExploitIssue TrackingVendor Advisory |
| https://github.com/shopware/shopware/issues/11245 | SEC Consult Vulnerability Lab | ExploitIssue TrackingVendor Advisory |
| http://seclists.org/fulldisclosure/2025/Aug/17 | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | SEC Consult Vulnerability Lab |
Affected Products
| Product | Versions |
|---|---|
| shopware shopware | >= 6.6.0.0, < 6.7.2.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | SEC Consult Vulnerability Lab |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Sep 10, 2025 | Initial Analysis | [email protected] |
| Aug 7, 2025 | CVE Modified | CISA-ADP |
| Aug 6, 2025 | New CVE Received | SEC Consult Vulnerability Lab |