shopper/framework vulnerabilities
CVEs whose affected-version data names the shopper/framework package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-56828High· 8.8Shopper: privilege escalation via improper Livewire admin component authorization
Shopper: privilege escalation via improper Livewire admin component authorization
▾ Twilightshopper · shopper/frameworkvia GHSA
CVE-2026-56826Medium· 5.4Shopping privilege escalation through missing authorization in Settings components
Shopping privilege escalation through missing authorization in Settings components
▾ Sunlitshopper · shopper/frameworkvia GHSA