Vulnerabilidades en shopperlabs
11 resultadosAnálisis Vexday
ShopperLabs possui 6 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando exposição recente e ativa do fornecedor. Embora nenhuma esteja sob exploração documentada (KEV), uma é crítica e a fraqueza dominante (CWE-862: falta de autorização) aponta para falhas no controle de acesso — risco material para integrações e dados sensíveis. A concentração temporal das divulgações sugere descobertas em sequência que demandam monitoramento contínuo.
CVE-2026-56825HIGHShopper: Missing authorization on product removal actions in CollectionProducts componentEPSS 0.5%CVE-2026-56829HIGHShopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock componentEPSS 0.5%CVE-2026-56827HIGHShopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliersEPSS 0.5%CVE-2026-56831MEDIUMShopper: Negative discount values accepted and propagated through order calculation pipelineEPSS 0.4%CVE-2026-47743HIGHShopper: Multiple data integrity and disclosure issues in admin Livewire componentsEPSS 0.4%CVE-2026-56830MEDIUMShopper: Incomplete fix for GHSA-h4mp-g9c6-xwph: Media sub-form store() still lacks authorizationEPSS 0.4%CVE-2026-47744CRITICALShopper: Authorization bypass and RBAC privilege escalation in team settingsEPSS 0.3%CVE-2026-47740HIGHShopper: Authorization bypass in multiple Livewire admin componentsEPSS 0.3%CVE-2026-47741MEDIUMShopper: Race condition on Discount.usage_limit allows silent over-redemptionEPSS 0.2%CVE-2026-47745MEDIUMShopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admin tablesEPSS 0.2%CVE-2026-47742MEDIUMShopper: Missing authorization on Product admin Livewire sub-form componentsEPSS 0.2%