shopify has 4 CVEs on record. The busiest recent month was January 2026 with 4. The median CVSS is 8.1 (high), with 1 rated critical. The most common weakness class is CWE-79 (3). Most affected products: react-router (2), react-router/node (1), remix-run/react (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
shopify vulnerabilities
CVEs affecting shopify, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-22029High· 8.0React Router is a router for React
React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, D…
CVE-2026-21884High· 8.2React Router is a router for React
React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/stora…
CVE-2025-59057High· 7.6PoCReact Router is a router for React
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating s…
CVE-2025-61686Critical· 9.1PoCReact Router is a router for React
React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/…