shopper/framework
[READ ONLY] Subtree split of the Shopper Admin Panel (see shopperlabs/framework)
Activity
- Latest release
- 3w ago
- Total releases
- 64
- Cadence
- ~3 days
- Last 12 months
- 38
Reach
- Stars
- 0
Details
- License
- MIT
- First release
- Aug 22, 2023
| Version | Released | |
|---|---|---|
v3.0.0-beta.6
pre
|
v3.0.0-beta.6
pre
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
v2.11.2
patch
|
v2.11.2
patch
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
v2.11.1
patch
|
v2.11.1
patch
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
v3.0.0-beta.5
pre
|
v3.0.0-beta.5
pre
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
v2.11.0
minor
| ||
v3.0.0-beta.4
pre
| ||
v2.10.2
patch
| ||
v3.0.0-beta.3
pre
|
v3.0.0-beta.3
pre
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
v2.10.1
patch
| ||
v2.10.0
minor
| ||
v3.0.0-beta.2
pre
| ||
v3.0.0-beta.1
pre
| ||
v2.9.2
patch
| ||
v2.9.1
patch
6 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56828
GHSA-j328-xmgp-j4q3
Sep 11, 2026
Shopper: privilege escalation via improper Livewire admin component authorization
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryThree Livewire admin components in A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)1)
| ||
v2.9.0
minor
6 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56828
GHSA-j328-xmgp-j4q3
Sep 11, 2026
Shopper: privilege escalation via improper Livewire admin component authorization
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryThree Livewire admin components in A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)1)
| ||
v2.8.1
patch
7 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56828
GHSA-j328-xmgp-j4q3
Sep 11, 2026
Shopper: privilege escalation via improper Livewire admin component authorization
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryThree Livewire admin components in A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)1)
|
v2.8.1
patch
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
v2.8.0
minor
7 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56828
GHSA-j328-xmgp-j4q3
Sep 11, 2026
Shopper: privilege escalation via improper Livewire admin component authorization
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryThree Livewire admin components in A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)1)
| ||
v2.7.3
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.7.2
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.7.1
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.7.0
minor
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
|
v2.7.0
minor
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
v2.6.4
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
|
v2.6.4
patch
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
v2.6.3
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.6.2
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.6.0
minor
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.5.1
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
|
v2.5.1
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
v2.5.0
minor
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
|
v2.5.0
minor
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
v2.4.3
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.4.0
minor
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.3.3
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.3.2
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.3
minor
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.2.7
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
|
v2.2.7
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v2.2.5
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.2.4
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.2.3
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.2.1
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.2
minor
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.1.6
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
|
v2.1.6
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v2.1.5
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.1.4
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.1.3
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
|
v2.1.3
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
v2.1.2
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.1.1
minor
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
|
v2.1.1
minor
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
v2.0.3
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
|
v2.0.3
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
v2.0.2
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.0.1
patch
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
|
v2.0.1
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
v2.0.0
initial
11 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56826
GHSA-f7h9-qv4x-9x57
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
SummaryFour Livewire components in the Settings area expose destructive Filament actions ( These records sit on the storefront checkout path, so deleting them breaks shipping-rate calculation, removes region-scoped payment methods, and corrupts tax resolution at checkout. This is inconsistent with the rest of the admin, where destructive actions are gated by granular permissions (e.g. Affected components| Component | File | Unauthorized action |
|---|---|---|
| Each file contains zero DetailsThe Settings pages mount these as child Livewire components. The parent page authorizes
Proof of ConceptConfirmed with the project's own test harness (Pest + Orchestra Testbench, SQLite) — the real Livewire/Filament code path, executed as a non-admin user holding only
Result:
The CONTROL case rules out a false positive: the same harness correctly denies ImpactA low-privileged staff member (or a compromised low-privileged account) can sabotage the storefront's checkout/revenue path without any delete permission:
Net effect: integrity and availability damage to live commerce configuration, performed by a principal who was never granted that authority (least-privilege violation). Secondary issue found while reproducing
Suggested remediationAdd an authorization check to each action, and ideally a
Apply to the Affected versions
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
+ 29 more Show less
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
| ||
v2.0.0-beta21
pre
10 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
|
v2.0.0-beta21
pre
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
v2.0.0-beta20
pre
10 CVEs
CVE-2026-56825
GHSA-2cg9-97gq-9mqp
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleMissing authorization on product removal actions in CollectionProducts component DescriptionA lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: any admin-panel account, including one whose role holds only
Proof of concept
ImpactA staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56830
GHSA-99h5-jhh7-v3r3
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
TitleMissing authorization on Media sub-form store action allows unpermissioned product media update DescriptionA lack of authorization control on the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Score: 6.5 (Medium) Affected files
The five sibling components that were fixed in commit fcd0c59 each now have:
Steps to reproducePrerequisites: an admin-panel account whose role holds
Proof of concept
ImpactA staff member with only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56829
GHSA-g3f9-g5vj-p62f
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
TitleUnauthorized inventory stock manipulation via unlocked variant property in VariantStock component DescriptionA lack of authorization control was discovered in the SeverityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High) Affected files
Steps to reproducePrerequisites: an admin-panel account with any role (including a role that holds only
Proof of concept
ImpactAny authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only Suggested fix
CreditsReported by Vishal Shukla (@shukla304 / @therawdev). Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 51 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.9.2
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56831
GHSA-5vf4-452p-jjhf
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
SummaryThe Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline. The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation. As a result, malformed discount records can influence financial calculations and produce unintended order totals. Affected ProductPackage: shopper/framework Version Tested: 2.8.1 Vulnerability Type
DescriptionWhile reviewing the discount functionality, it was discovered that the application accepts negative discount values through the administrative interface. Example values tested:
The application accepted these values without validation and stored them in the database. Example records observed in the
This demonstrates that negative discount values are successfully persisted. Steps to Reproduce1. Create a DiscountLogin as an administrator. Navigate to:
Create a new discount with the following values:
Save the discount. 2. Observe Successful CreationThe discount is accepted by the application and displayed in the administration interface. Example:
3. Verify Database PersistenceInspect the database:
Observed entry:
Technical AnalysisDiscount CalculationFile:
Observed code:
The value is later processed without validation:
When a negative value is supplied:
returns:
allowing the negative value to continue through the calculation pipeline. The resulting adjustment values are inserted into the database:
No validation was identified to ensure that discount amounts are positive before calculations occur. Final Total CalculationFile:
Observed logic:
Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data. Example:
Resulting calculation:
Result:
This demonstrates that negative discount values directly affect order total calculations. ImpactThe following was confirmed:
Potential consequences include:
Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, it was not verified a customer-facing exploitation path. However, malformed discount records currently propagate through pricing calculations without validation. RecommendationImplement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline. Suggested validation: Fixed Amount Discounts
Percentage Discounts
Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic. Environment
Affected versions
v2.0.0
v2.0.0-alpha
v2.0.0-beta
v2.0.0-beta10
v2.0.0-beta11
v2.0.0-beta12
v2.0.0-beta13
v2.0.0-beta14
v2.0.0-beta15
v2.0.0-beta16
v2.0.0-beta17
v2.0.0-beta18
+ 49 more Show less
v2.0.0-beta19
v2.0.0-beta2
v2.0.0-beta20
v2.0.0-beta21
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2.0.0-beta6
v2.0.0-beta7
v2.0.0-beta8
v2.0.0-beta9
v2.0.1
v2.0.2
v2.0.3
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.8.0
v2.8.1
Fixed in
2.9.0
References Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-56827
GHSA-243p-f3cv-c5wh
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryFive Filament A staff user holding only CVSS 3.1: Vulnerable components (paths relative to repo root)All references are HEAD = commit 1)
|