shopper/framework
Packagist12 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting shopper/frameworkpage 1 of 1
- CVE-2026-47740HIGHCVSS 8.1EG 8.1fixed in 2.8.02026-05-29
vulnerable: v2.0.0 ... v2.7.3 (59 versions)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orde…
- CVE-2026-47742MEDIUMCVSS 6.5EG 6.5fixed in 2.8.02026-05-29
vulnerable: v2.0.0 ... v2.7.3 (59 versions)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() method. Any authenticated panel user, regar…
- CVE-2026-47743HIGHCVSS 8.7EG 8.7fixed in 2.8.02026-06-05
vulnerable: v2.0.0 ... v2.7.3 (59 versions)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel expos…
- CVE-2026-47744CRITICALCVSS 9.9EG 9.9fixed in 2.8.02026-05-29
vulnerable: v2.0.0 ... v2.7.3 (59 versions)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any …
- CVE-2026-47745MEDIUMCVSS 6.5EG 6.5fixed in 2.8.02026-05-29
vulnerable: v2.0.0 ... v2.7.3 (59 versions)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, disable, edit, delete) that were rendered for any authenticat…
- CVE-2026-56825HIGHCVSS 8.1EG 8.1fixed in 2.9.22026-09-11
vulnerable: v2.0.0 ... v2.9.1 (63 versions)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/CollectionProducts.php exposes Action::make('delete') and DeleteBulkAction::make() without delete_collections authorization, wh…
- CVE-2026-56826MEDIUMCVSS 5.4EG 5.4fixed in 2.9.22026-09-11
vulnerable: v2.0.0 ... v2.9.1 (41 versions)
Shopping privilege escalation through missing authorization in Settings components ## Summary Four Livewire components in the Settings area expose destructive Filament actions (`delete` / `edit`) that perform **no server-side authorizati…
- CVE-2026-56827HIGHCVSS 8.1EG 8.1fixed in 2.9.22026-09-11
vulnerable: v2.0.0 ... v2.9.1 (63 versions)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/Attribute/Browse.php, packages/admin/src/Livewire/Pages/Tag/Index.php, packages/admin/src/Livewire/Pages/Brand/Index.php,…
- CVE-2026-56828HIGHCVSS 8.8EG 8.8fixed in 2.9.22026-09-11
vulnerable: v2.8.0, v2.8.1, v2.9.0, v2.9.1
Shopper: privilege escalation via improper Livewire admin component authorization ## Summary Three Livewire admin components in `shopper/framework` (latest master at commit `fcd0c59`, released as v2.8.0) gate state-mutating actions on th…
- CVE-2026-56829HIGHCVSS 8.1EG 8.1fixed in 2.9.22026-09-11
vulnerable: v2.0.0 ... v2.9.1 (63 versions)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable beca…
- CVE-2026-56830MEDIUMCVSS 6.5EG 6.5fixed in 2.9.22026-09-11
vulnerable: v2.0.0 ... v2.9.1 (63 versions)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used by…
- CVE-2026-56831MEDIUMCVSS 6.5EG 6.5fixed in 2.9.02026-09-11
vulnerable: v2.0.0 ... v2.8.1 (61 versions)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Disc…
Check whether shopper/framework is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for shopper/framework CVEs against the assets you own.
Book a Demo →