Skip to content
Noroxi

Shopify records

21 published records for vendor shopify.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

21 records
  • React Router has Path Traversal in File Session Storage

    CriticalCVSS 9.1Proof of conceptEPSS 17%

    shopify · react-router\/nodeJan 9, 2026

  • React Router: Unauthenticated Denial of Service via Inefficient Route Matching

    HighCVSS 8.7No exploitEPSS 1%

    shopify · react-routerJul 27, 2026

  • React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE

    HighCVSS 8.1No exploitEPSS 1%

    shopify · react-routerJun 2, 2026

  • React Router SSR XSS in ScrollRestoration

    HighCVSS 8.2No exploitEPSS 1%

    shopify · react-routerJan 9, 2026

  • React Router has XSS Vulnerability

    HighCVSS 7.6Proof of conceptEPSS 1%

    shopify · react-routerJan 9, 2026

  • React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint

    HighCVSS 7.5No exploitEPSS 0%

    shopify · react-routerJun 2, 2026

  • React Router vulnerable to Denial of Service via reflected user input in single-fetch

    HighCVSS 7.5No exploitEPSS 0%

    shopify · react-routerJun 2, 2026

  • Ruby LSP has arbitrary code execution through branch setting

    HighCVSS 7.1No exploitEPSS 1%

    shopify · ruby lspMar 30, 2026

  • React Router: Open redirect can lead to XSS

    MediumCVSS 6.9No exploitEPSS 0%

    shopify · react-routerJul 27, 2026

  • React Router has unexpected external redirect via untrusted paths

    MediumCVSS 6.5No exploitEPSS 0%

    shopify · react-routerJan 9, 2026

  • React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation

    MediumCVSS 6.6No exploitEPSS 0%

    shopify · react-routerJun 2, 2026

  • React Router has CSRF issue in Action/Server Action Request Processing

    MediumCVSS 6.5No exploitEPSS 0%

    shopify · react-routerJan 9, 2026

  • Tophat has a Command Injection Vulnerability When Accessing a Maliciously Crafted Tophat Link

    MediumCVSS 6.3No exploitEPSS 1%

    shopify · tophatApr 8, 2026

  • CVE-2020-8176
    24Monitor

    A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop

    MediumCVSS 6.1No exploitEPSS 1%

    shopify · koa-shopify-authJul 2, 2020

  • React Router vulnerable to XSS via Open Redirects

    MediumCVSS 6.1No exploitEPSS 1%

    shopify · remix-run\/reactJan 9, 2026

  • React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration

    MediumCVSS 6.1No exploitEPSS 0%

    shopify · react-routerJul 27, 2026

  • React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667)

    MediumCVSS 6.1No exploitEPSS 0%

    shopify · react-routerJul 27, 2026

  • Potential cross-site scripting (XSS) vulnerability in Hydrogen

    MediumCVSS 5.4No exploitEPSS 1%

    shopify · hydrogenMay 18, 2022

  • React Router has stored XSS via unescaped Location header in prerendered redirect HTML

    MediumCVSS 5.4No exploitEPSS 0%

    shopify · react-routerJun 2, 2026

  • React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)

    MediumCVSS 5.1No exploitEPSS 0%

    shopify · react-routerJul 27, 2026

  • React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets

    MediumCVSS 4.7No exploitEPSS 0%

    shopify · react-routerJun 2, 2026