Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Shopper — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in Shopper, with AI-generated Chinese analysis, references, and POCs.

Vendor: shopperdotcom

CVE ID Title CVSS Severity Published
CVE-2026-56830 Shopper: Incomplete fix for GHSA-h4mp-g9c6-xwph: Media sub-form store() still lacks authorization CWE-862 6.5 Medium 2026-09-15
CVE-2026-56831 Shopper: Negative discount values accepted and propagated through order calculation pipeline CWE-20 6.5 Medium 2026-09-15
CVE-2026-56827 Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers CWE-862 8.1 High 2026-09-15
CVE-2026-56829 Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component CWE-862 8.1 High 2026-09-15
CVE-2026-56825 Shopper: Missing authorization on product removal actions in CollectionProducts component CWE-862 8.1 High 2026-09-15
CVE-2026-47743 Shopper: Multiple data integrity and disclosure issues in admin Livewire components CWE-79 8.7 High 2026-07-23
CVE-2026-47740 Shopper: Authorization bypass in multiple Livewire admin components CWE-285 8.1 High 2026-05-29
CVE-2026-47741 Shopper: Race condition on Discount.usage_limit allows silent over-redemption CWE-362 5.9 Medium 2026-05-29
CVE-2026-47742 Shopper: Missing authorization on Product admin Livewire sub-form components CWE-862 6.5 Medium 2026-05-29
CVE-2026-47744 Shopper: Authorization bypass and RBAC privilege escalation in team settings CWE-269 9.9 Critical 2026-05-29
CVE-2026-47745 Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admin tables CWE-862 6.5 Medium 2026-05-29
CVE-2025-31534 WordPress Shopper plugin <= 3.2.5 - SQL Injection vulnerability CWE-89 9.3 Critical 2025-04-01

All 12 known CVE vulnerabilities affecting Shopper with full Chinese analysis, references, and POCs where available.