E-commerce Admin Panel Vulnerabilities in Shopper Affecting Data Security
CVE-2026-47743

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-47743?

Shopper's headless e-commerce admin panel has several vulnerabilities related to the use of Livewire components that could lead to critical security issues. These include data tampering, as authenticated users can manipulate wire payloads to access unintended records. There is also a severe risk of sensitive data disclosure due to plaintext passwords being rendered in the HTML and logged openly via Livewire snapshots. Additionally, the product barcode field is exploitable, allowing attackers with specific permissions to inject malicious payloads that could execute in the browser of any administrator. Recent updates have introduced mitigating measures such as locking vulnerable identifiers, securing password handling, and properly escaping output, yet no workarounds were available prior to version 2.8.0.

Affected Version(s)

shopper < 2.8.0

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.