Discount Calculation Flaw in Shopper E-commerce Admin Panel
CVE-2026-56831
6.5MEDIUM
What is CVE-2026-56831?
The Shopper e-commerce Admin Panel contains a vulnerability in its /cpanel/discounts administrative interface that improperly handles negative fixed_amount discount values prior to version 2.9.0. This flaw allows for negative discounts to be stored and processed without validation, leading to incorrect pricing. When such discounts are applied, they erroneously increase the total order amount instead of reducing it. While the vulnerability does not present a direct customer-facing exploitation pathway, it poses risks related to inaccurate pricing and fails to maintain financial data integrity. This issue has been resolved in version 2.9.0.
Affected Version(s)
shopper < 2.9.0
