cbcvebase.

Shopperlabs Shopper vulnerabilities

11 known vulnerabilities affecting shopperlabs/shopper.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2026-47744P2CRITICALCVSS 9.9fixed in 2.8.02026-05-29
CVE-2026-47744 [CRITICAL] CWE-269 CVE-2026-47744: Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any authenticated user could load the page and use its public actions to create new roles and delete other users, i
nvd
CVE-2026-56825P3HIGHCVSS 8.1fixed in 2.9.22026-09-15
CVE-2026-56825 [HIGH] CWE-862 CVE-2026-56825: Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/CollectionProducts.php exposes Action::make('delete') and DeleteBulkAction::make() without delete_collections authorization, while public Collection $collection remains client mutable because it lacks the Livewire Locked attribute. An authen
nvd
CVE-2026-56829P3HIGHCVSS 8.1fixed in 2.9.22026-09-15
CVE-2026-56829 [HIGH] CWE-862 CVE-2026-56829: Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable because it lacks the Livewire Locked attribute. Any authenticated admin-panel user, including staff with only browse_p
nvd
CVE-2026-47740P3HIGHCVSS 8.1fixed in 2.8.02026-05-29
CVE-2026-47740 [HIGH] CWE-285 CVE-2026-47740: Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orders. The order detail actions cancel, mark paid, mark complete, capture payment, archive, and start processing were
nvd
CVE-2026-56827P3HIGHCVSS 8.1fixed in 2.9.22026-09-15
CVE-2026-56827 [HIGH] CWE-862 CVE-2026-56827: Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/s Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/Attribute/Browse.php, packages/admin/src/Livewire/Pages/Tag/Index.php, packages/admin/src/Livewire/Pages/Brand/Index.php, packages/admin/src/Livewire/Pages/Category/Index.php, and packages/admin/src/Livewire/Pages/Supplier/Index.php om
nvd
CVE-2026-47743P3HIGHCVSS 8.7fixed in 2.8.02026-07-23
CVE-2026-47743 [HIGH] CWE-79 CVE-2026-47743: Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewir Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent model identifiers as public properties without the `#[Locked]` attribute. An authenticated user could r
nvd
CVE-2026-47742P3MEDIUMCVSS 6.5fixed in 2.8.02026-05-29
CVE-2026-47742 [MEDIUM] CWE-862 CVE-2026-47742: Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in t Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() method. Any authenticated panel user, regardless of role, could mutate any product's pricing, stock, SEO metadata, shipping dimensions, and attached media
nvd
CVE-2026-56831P3MEDIUMCVSS 6.5fixed in 2.9.02026-09-15
CVE-2026-56831 [MEDIUM] CWE-20 CVE-2026-56831: Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative i Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Discounts/DiscountCalculator.php and vendor/shopper/cart/src/Pipelines/Calculate.php without enforcing a positive-val
nvd
CVE-2026-56830P3MEDIUMCVSS 6.5fixed in 2.9.22026-09-15
CVE-2026-56830 [MEDIUM] CWE-862 CVE-2026-56830: Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used by sibling sub-forms. An authenticated staff user with browse_products can invoke the Livewire store action and rep
nvd
CVE-2026-47745P3MEDIUMCVSS 6.5fixed in 2.8.02026-05-29
CVE-2026-47745 [MEDIUM] CWE-862 CVE-2026-47745: Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, C Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, disable, edit, delete) that were rendered for any authenticated panel user without checking the corresponding per-action permission. A low-privilege user could disable every
nvd
CVE-2026-47741P4MEDIUMCVSS 5.9fixed in 2.8.02026-05-29
CVE-2026-47741 [MEDIUM] CWE-362 CVE-2026-47741: Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute pre Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Under concurrent checkout pressure (Black Friday, flash sale, viral coupon), the global usage_limit was silently exceeded: orders were committed with the
nvd
Shopperlabs Shopper vulnerabilities | cvebase