{"id":"CVE-2025-7954","summary":"Race Condition in Shopware Voucher Submission","details":"A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.","aliases":["GHSA-27gv-mg7w-mm34"],"modified":"2026-08-12T03:51:27.541243614Z","published":"2025-08-06T07:16:09.712Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"6.6.x"},{"last_affected":"6.6.x"},{"introduced":"6.7.x"},{"last_affected":"6.7.x"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"SEC-VLab","cwe_ids":["CWE-362"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7954.json"},"references":[{"type":"WEB","url":"http://seclists.org/fulldisclosure/2025/Aug/17"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7954.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-7954"},{"type":"REPORT","url":"https://github.com/shopware/shopware/issues/11245"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/shopware/shopware","events":[{"introduced":"b0ae9ef3fae80afcc4f38401c09037fa7adc57b0"},{"fixed":"681bfeca42d60bbf9110a635956e621e1d1c4969"}],"database_specific":{"cpe":"cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.6.0.0"},{"fixed":"6.7.2.0"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7954.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N"}]}