Shopify records
21 published records for vendor shopify.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-400 Uncontrolled Resource Consumption2
- CWE-502 Deserialization of Untrusted Data1
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2025-61686Proof of concept | React Router has Path Traversal in File Session Storageshopify · react-router\/node · CWE-22 | Critical9.1 | — | 17.3% | Jan 9, 2026 |
34Monitor | CVE-2026-55685No exploit | React Router: Unauthenticated Denial of Service via Inefficient Route Matchingshopify · react-router · CWE-400 | High8.7 | — | 0.7% | Jul 27, 2026 |
32Monitor | CVE-2026-42211No exploit | React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCEshopify · react-router · CWE-502 | High8.1 | — | 0.6% | Jun 2, 2026 |
32Monitor | CVE-2026-21884No exploit | React Router SSR XSS in ScrollRestorationshopify · react-router · CWE-79 | High8.2 | — | 0.5% | Jan 9, 2026 |
30Monitor | CVE-2025-59057Proof of concept | React Router has XSS Vulnerabilityshopify · react-router · CWE-79 | High7.6 | — | 0.5% | Jan 9, 2026 |
30Monitor | CVE-2026-42342No exploit | React Router vulnerable to DoS via unbounded path expansion in __manifest endpointshopify · react-router · CWE-400 | High7.5 | — | 0.5% | Jun 2, 2026 |
30Monitor | CVE-2026-34077No exploit | React Router vulnerable to Denial of Service via reflected user input in single-fetchshopify · react-router · CWE-770 | High7.5 | — | 0.5% | Jun 2, 2026 |
28Monitor | CVE-2026-34060No exploit | Ruby LSP has arbitrary code execution through branch settingshopify · ruby lsp · CWE-94 | High7.1 | — | 0.6% | Mar 30, 2026 |
27Monitor | CVE-2026-53668No exploit | React Router: Open redirect can lead to XSSshopify · react-router · CWE-79 | Medium6.9 | — | 0.3% | Jul 27, 2026 |
26Monitor | CVE-2025-68470No exploit | React Router has unexpected external redirect via untrusted pathsshopify · react-router · CWE-601 | Medium6.5 | — | 0.5% | Jan 9, 2026 |
26Monitor | CVE-2026-40181No exploit | React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretationshopify · react-router · CWE-601 | Medium6.6 | — | 0.3% | Jun 2, 2026 |
26Monitor | CVE-2026-22030No exploit | React Router has CSRF issue in Action/Server Action Request Processingshopify · react-router · CWE-346 | Medium6.5 | — | 0.2% | Jan 9, 2026 |
25Monitor | CVE-2026-39862No exploit | Tophat has a Command Injection Vulnerability When Accessing a Maliciously Crafted Tophat Linkshopify · tophat · CWE-78 | Medium6.3 | — | 1.1% | Apr 8, 2026 |
24Monitor | CVE-2020-8176No exploit | A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shopshopify · koa-shopify-auth · CWE-79 | Medium6.1 | — | 1.0% | Jul 2, 2020 |
24Monitor | CVE-2026-22029No exploit | React Router vulnerable to XSS via Open Redirectsshopify · remix-run\/react · CWE-79 | Medium6.1 | — | 0.9% | Jan 9, 2026 |
24Monitor | CVE-2026-53666No exploit | React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydrationshopify · react-router · CWE-470 | Medium6.1 | — | 0.4% | Jul 27, 2026 |
24Monitor | CVE-2026-53667No exploit | React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667)shopify · react-router · CWE-79 | Medium6.1 | — | 0.4% | Jul 27, 2026 |
21Monitor | CVE-2022-29230No exploit | Potential cross-site scripting (XSS) vulnerability in Hydrogenshopify · hydrogen · CWE-79 | Medium5.4 | — | 0.8% | May 18, 2022 |
21Monitor | CVE-2026-33244No exploit | React Router has stored XSS via unescaped Location header in prerendered redirect HTMLshopify · react-router · CWE-79 | Medium5.4 | — | 0.1% | Jun 2, 2026 |
20Monitor | CVE-2026-53669No exploit | React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)shopify · react-router · CWE-601 | Medium5.1 | — | 0.3% | Jul 27, 2026 |
18Monitor | CVE-2026-33245No exploit | React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targetsshopify · react-router · CWE-79 | Medium4.7 | — | 0.2% | Jun 2, 2026 |
- CVE-2025-6168641Plan
React Router has Path Traversal in File Session Storage
CriticalCVSS 9.1Proof of conceptEPSS 17%shopify · react-router\/nodeJan 9, 2026
- CVE-2026-5568534Monitor
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
HighCVSS 8.7No exploitEPSS 1%shopify · react-routerJul 27, 2026
- CVE-2026-4221132Monitor
React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
HighCVSS 8.1No exploitEPSS 1%shopify · react-routerJun 2, 2026
- CVE-2026-2188432Monitor
React Router SSR XSS in ScrollRestoration
HighCVSS 8.2No exploitEPSS 1%shopify · react-routerJan 9, 2026
- CVE-2025-5905730Monitor
React Router has XSS Vulnerability
HighCVSS 7.6Proof of conceptEPSS 1%shopify · react-routerJan 9, 2026
- CVE-2026-4234230Monitor
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
HighCVSS 7.5No exploitEPSS 0%shopify · react-routerJun 2, 2026
- CVE-2026-3407730Monitor
React Router vulnerable to Denial of Service via reflected user input in single-fetch
HighCVSS 7.5No exploitEPSS 0%shopify · react-routerJun 2, 2026
- CVE-2026-3406028Monitor
Ruby LSP has arbitrary code execution through branch setting
HighCVSS 7.1No exploitEPSS 1%shopify · ruby lspMar 30, 2026
- CVE-2026-5366827Monitor
React Router: Open redirect can lead to XSS
MediumCVSS 6.9No exploitEPSS 0%shopify · react-routerJul 27, 2026
- CVE-2025-6847026Monitor
React Router has unexpected external redirect via untrusted paths
MediumCVSS 6.5No exploitEPSS 0%shopify · react-routerJan 9, 2026
- CVE-2026-4018126Monitor
React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation
MediumCVSS 6.6No exploitEPSS 0%shopify · react-routerJun 2, 2026
- CVE-2026-2203026Monitor
React Router has CSRF issue in Action/Server Action Request Processing
MediumCVSS 6.5No exploitEPSS 0%shopify · react-routerJan 9, 2026
- CVE-2026-3986225Monitor
Tophat has a Command Injection Vulnerability When Accessing a Maliciously Crafted Tophat Link
MediumCVSS 6.3No exploitEPSS 1%shopify · tophatApr 8, 2026
- CVE-2020-817624Monitor
A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop
MediumCVSS 6.1No exploitEPSS 1%shopify · koa-shopify-authJul 2, 2020
- CVE-2026-2202924Monitor
React Router vulnerable to XSS via Open Redirects
MediumCVSS 6.1No exploitEPSS 1%shopify · remix-run\/reactJan 9, 2026
- CVE-2026-5366624Monitor
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
MediumCVSS 6.1No exploitEPSS 0%shopify · react-routerJul 27, 2026
- CVE-2026-5366724Monitor
React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667)
MediumCVSS 6.1No exploitEPSS 0%shopify · react-routerJul 27, 2026
- CVE-2022-2923021Monitor
Potential cross-site scripting (XSS) vulnerability in Hydrogen
MediumCVSS 5.4No exploitEPSS 1%shopify · hydrogenMay 18, 2022
- CVE-2026-3324421Monitor
React Router has stored XSS via unescaped Location header in prerendered redirect HTML
MediumCVSS 5.4No exploitEPSS 0%shopify · react-routerJun 2, 2026
- CVE-2026-5366920Monitor
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
MediumCVSS 5.1No exploitEPSS 0%shopify · react-routerJul 27, 2026
- CVE-2026-3324518Monitor
React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets
MediumCVSS 4.7No exploitEPSS 0%shopify · react-routerJun 2, 2026