CVE-2026-56831
published 2026-09-15CVE-2026-56831: Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values…
PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.41%
34.6th percentile
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Discounts/DiscountCalculator.php and vendor/shopper/cart/src/Pipelines/Calculate.php without enforcing a positive-value invariant. Because the calculation subtracts discountTotal from the subtotal, a negative discount increases the resulting order total instead of reducing it. Malformed discount records can therefore cause incorrect pricing and financial data integrity failures, although the advisory does not establish a customer-facing exploitation path. This issue is fixed in version 2.9.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| shopper | framework | >= 0 < 2.9.0 | 2.9.0 |
| shopperlabs | shopper | < 2.9.0 | 2.9.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Shopper Framework 2.8.1 Discount Calculation DiscountCalculator.php Value input validation
vuldb·2026-09-12
CVE-2026-56831 [LOW] Shopper Framework 2.8.1 Discount Calculation DiscountCalculator.php Value input validation
A vulnerability classified as problematic has been found in Shopper Framework 2.8.1. Affected is an unknown function of the file vendor/shopper/cart/src/Discounts/DiscountCalculator.php of the component Discount Calculation. Performing a manipulation of the argument Value results in improper input validation.
This vulnerability is reported as CVE-2026-56831. The attack is possible to be carried out remotely. No exploit exists.
GHSA
Shopper: Negative discount values accepted and propagated through order calculation pipeline
ghsa·2026-09-11
CVE-2026-56831 [MEDIUM] CWE-20 Shopper: Negative discount values accepted and propagated through order calculation pipeline
Shopper: Negative discount values accepted and propagated through order calculation pipeline
## Summary
The Shopper Framework discount management functionality accepts negative discount values without server-side validation.
It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline.
The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation.
As a result, malformed discount records can influence financial calculations and produce unintended order totals.
---
## Affected Product
**Package:** shopper/framework
**Version Tested:** 2.8.1
---
## Vulnera
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/shopperlabs/shopper/commit/967e616281ded1a0050d9102858ecd7dd7f66a41https://github.com/shopperlabs/shopper/pull/528https://github.com/shopperlabs/shopper/releases/tag/v2.9.0https://github.com/shopperlabs/shopper/security/advisories/GHSA-5vf4-452p-jjhfhttps://github.com/shopperlabs/shopper/security/advisories/GHSA-5vf4-452p-jjhf
2026-09-15
Published