VulnSea

shopperlabs has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 8.1 (high). None have a confirmed exploitation report. The most common weakness class is CWE-862 (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.1
Publish → KEV
Last 90 days
5 prev 0

Weakness classes

Products

  • shopper 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

shopperlabs vulnerabilities

CVEs affecting shopperlabs, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-56831Medium· 6.5PoC
6d ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Di…

Twilightshopperlabs · shopperEPSS 0.41%via NVD
CVE-2026-56830Medium· 6.5
6d ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used …

Sunlitshopperlabs · shopperEPSS 0.36%via NVD
CVE-2026-56829High· 8.1PoC
6d ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable be…

Midnightshopperlabs · shopperEPSS 0.47%via NVD
CVE-2026-56827High· 8.1PoC
6d ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/Attribute/Browse.php, packages/admin/src/Livewire/Pages/Tag/Index.php, packages/admin/src/Livewire/Pages/Brand/Index.ph…

Midnightshopperlabs · shopperEPSS 0.47%via NVD
CVE-2026-56825High· 8.1PoC
6d ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/CollectionProducts.php exposes Action::make('delete') and DeleteBulkAction::make() without delete_collections authorization, …

Midnightshopperlabs · shopperEPSS 0.47%via NVD
shopperlabs vulnerabilities (CVEs) · VulnSea