shopper/framework Security Advisories for v2.9.1 (6)
-
[HIGH] Shopper: Missing authorization on product removal actions in CollectionProducts component
PKSA-b41c-cwpv-9733 CVE-2026-56825 GHSA-2cg9-97gq-9mqp
Affected version: <2.9.2
Reported by:
GitHub -
[MEDIUM] Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
PKSA-xbk1-5yr7-c54k CVE-2026-56830 GHSA-99h5-jhh7-v3r3
Affected version: <2.9.2
Reported by:
GitHub -
[HIGH] Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
PKSA-d6w1-f12g-cj15 CVE-2026-56829 GHSA-g3f9-g5vj-p62f
Affected version: <2.9.2
Reported by:
GitHub -
[HIGH] Shopper: privilege escalation via improper Livewire admin component authorization
PKSA-5w3n-c3b1-mxqj CVE-2026-56828 GHSA-j328-xmgp-j4q3
Affected version: >=2.8.0,<2.9.2
Reported by:
GitHub -
[MEDIUM] Shopping privilege escalation through missing authorization in Settings components
PKSA-kzx5-8h8q-mx1w CVE-2026-56826 GHSA-f7h9-qv4x-9x57
Affected version: >=2.0.0,<2.9.2
Reported by:
GitHub