CVE-2025-7954

EPSS 0.25%

Shopware race condition bypasses voucher restrictions

Published: 8/6/2025Modified: 11/3/2025
Also known as:GHSA-27gv-mg7w-mm34

Description

A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

References (4)