VulnSea

shopper vulnerabilities

CVEs whose affected-version data names the shopper package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-56831Medium· 6.5PoC
1w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Di…

Twilightshopperlabs · shopperEPSS 0.41%via NVD
CVE-2026-56830Medium· 6.5
1w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used …

Sunlitshopperlabs · shopperEPSS 0.36%via NVD
CVE-2026-56829High· 8.1PoC
1w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable be…

Midnightshopperlabs · shopperEPSS 0.47%via NVD
CVE-2026-56827High· 8.1PoC
1w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/Attribute/Browse.php, packages/admin/src/Livewire/Pages/Tag/Index.php, packages/admin/src/Livewire/Pages/Brand/Index.ph…

Midnightshopperlabs · shopperEPSS 0.47%via NVD
CVE-2026-56825High· 8.1PoC
1w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/CollectionProducts.php exposes Action::make('delete') and DeleteBulkAction::make() without delete_collections authorization, …

Midnightshopperlabs · shopperEPSS 0.47%via NVD
shopper vulnerabilities (CVEs) · VulnSea