漏洞描述翻译: Shopper 是一个无头(Headless)电子商务管理面板。在 2.9.2 版本之前, 中的 和 在未授予 权限的情况下被暴露出来。同时,公共变量 因缺少 Livewire 的 属性,从而允许客户端修改其值。 一名仅拥有 权限的已认证员工用户可以调用 Livewire 删除操作,替换为任意的集合标识符,从而将选定的商品从集合中移除,或使集合变空。这可能会扰乱与目标集合相关的商品目录落地页和促销活动。 该问题已在版本 2.9.2 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| shopperlabs | shopper | < 2.9.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| shopperlabs | shopper | < 2.9.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56827 | 8.1 HIGH | Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-de |
| CVE-2026-56829 | 8.1 HIGH | Shopper: Unauthorized inventory stock manipulation via unlocked variant property in Varian |
| CVE-2026-56830 | 6.5 MEDIUM | Shopper: Incomplete fix for GHSA-h4mp-g9c6-xwph: Media sub-form store() still lacks author |
| CVE-2026-56831 | 6.5 MEDIUM | Shopper: Negative discount values accepted and propagated through order calculation pipeli |
No comments yet