shopper/framework Security Advisories (12)
-
[HIGH] Shopper: Missing authorization on product removal actions in CollectionProducts component
PKSA-b41c-cwpv-9733 CVE-2026-56825 GHSA-2cg9-97gq-9mqp
Affected version: <2.9.2
Reported by:
GitHub -
[MEDIUM] Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
PKSA-xbk1-5yr7-c54k CVE-2026-56830 GHSA-99h5-jhh7-v3r3
Affected version: <2.9.2
Reported by:
GitHub -
[HIGH] Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
PKSA-d6w1-f12g-cj15 CVE-2026-56829 GHSA-g3f9-g5vj-p62f
Affected version: <2.9.2
Reported by:
GitHub -
[HIGH] Shopper: privilege escalation via improper Livewire admin component authorization
PKSA-5w3n-c3b1-mxqj CVE-2026-56828 GHSA-j328-xmgp-j4q3
Affected version: >=2.8.0,<2.9.2
Reported by:
GitHub -
[MEDIUM] Shopping privilege escalation through missing authorization in Settings components
PKSA-kzx5-8h8q-mx1w CVE-2026-56826 GHSA-f7h9-qv4x-9x57
Affected version: >=2.0.0,<2.9.2
Reported by:
GitHub -
[MEDIUM] Shopper: Negative discount values accepted and propagated through order calculation pipeline
PKSA-j6gh-mr7c-jrwc CVE-2026-56831 GHSA-5vf4-452p-jjhf
Affected version: <2.9.0
Reported by:
GitHub -
[CRITICAL] Shopper: Authorization bypass and RBAC privilege escalation in team settings
PKSA-5g52-7x8y-w2y1 CVE-2026-47744 GHSA-c3qp-2ggw-xjg7
Affected version: <2.8.0
Reported by:
GitHub -
[HIGH] Shopper: Multiple data integrity and disclosure issues in admin Livewire components
PKSA-88dm-mp91-mkr8 CVE-2026-47743 GHSA-hr9v-r8r2-hg7j
Affected version: <2.8.0
Reported by:
GitHub -
[MEDIUM] Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admin tables
PKSA-7v8h-262h-wzkz CVE-2026-47745 GHSA-fxqw-97cc-7g5c
Affected version: <2.8.0
Reported by:
GitHub -
[MEDIUM] Shopper: Missing authorization on Product admin Livewire sub-form components
PKSA-jg8p-p13z-fkym CVE-2026-47742 GHSA-h4mp-g9c6-xwph
Affected version: <2.8.0
Reported by:
GitHub -
[HIGH] shopper/framework: Authorization bypass in multiple Livewire admin components
PKSA-vtqh-k648-prz7 CVE-2026-47740 GHSA-f946-9qp6-vgch
Affected version: <2.8.0
Reported by:
GitHub