shopperlabs has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 8.1 (high). None have a confirmed exploitation report. The most common weakness class is CWE-862 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Worst active — by depth score
CVE-2026-56829High· 8.1Shopper is a Headless e-commerce Admin Panel57CVE-2026-56827High· 8.1Shopper is a Headless e-commerce Admin Panel57CVE-2026-56825High· 8.1Shopper is a Headless e-commerce Admin Panel57CVE-2026-56831Medium· 6.5Shopper is a Headless e-commerce Admin Panel48CVE-2026-56830Medium· 6.5Shopper is a Headless e-commerce Admin Panel36
shopperlabs vulnerabilities
CVEs affecting shopperlabs, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-56831Medium· 6.5PoCShopper is a Headless e-commerce Admin Panel
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Di…
CVE-2026-56830Medium· 6.5Shopper is a Headless e-commerce Admin Panel
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used …
CVE-2026-56829High· 8.1PoCShopper is a Headless e-commerce Admin Panel
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable be…
CVE-2026-56827High· 8.1PoCShopper is a Headless e-commerce Admin Panel
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/Attribute/Browse.php, packages/admin/src/Livewire/Pages/Tag/Index.php, packages/admin/src/Livewire/Pages/Brand/Index.ph…
CVE-2026-56825High· 8.1PoCShopper is a Headless e-commerce Admin Panel
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/CollectionProducts.php exposes Action::make('delete') and DeleteBulkAction::make() without delete_collections authorization, …