Записи Shopify
21 опубликованных записей вендора shopify.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-400 Uncontrolled Resource Consumption2
- CWE-502 Deserialization of Untrusted Data1
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2025-61686Proof of concept | React Router has Path Traversal in File Session Storageshopify · react-router\/node · CWE-22 | Критическая9,1 | — | 17,6 % | 9 янв. 2026 г. |
34Наблюдать | CVE-2026-55685Эксплойта нет | React Router: Unauthenticated Denial of Service via Inefficient Route Matchingshopify · react-router · CWE-400 | Высокая8,7 | — | 0,7 % | 27 июл. 2026 г. |
32Наблюдать | CVE-2026-42211Эксплойта нет | React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCEshopify · react-router · CWE-502 | Высокая8,1 | — | 0,6 % | 2 июн. 2026 г. |
32Наблюдать | CVE-2026-21884Эксплойта нет | React Router SSR XSS in ScrollRestorationshopify · react-router · CWE-79 | Высокая8,2 | — | 0,5 % | 9 янв. 2026 г. |
30Наблюдать | CVE-2025-59057Proof of concept | React Router has XSS Vulnerabilityshopify · react-router · CWE-79 | Высокая7,6 | — | 0,5 % | 9 янв. 2026 г. |
30Наблюдать | CVE-2026-42342Эксплойта нет | React Router vulnerable to DoS via unbounded path expansion in __manifest endpointshopify · react-router · CWE-400 | Высокая7,5 | — | 0,5 % | 2 июн. 2026 г. |
30Наблюдать | CVE-2026-34077Эксплойта нет | React Router vulnerable to Denial of Service via reflected user input in single-fetchshopify · react-router · CWE-770 | Высокая7,5 | — | 0,5 % | 2 июн. 2026 г. |
28Наблюдать | CVE-2026-34060Эксплойта нет | Ruby LSP has arbitrary code execution through branch settingshopify · ruby lsp · CWE-94 | Высокая7,1 | — | 0,6 % | 30 мар. 2026 г. |
27Наблюдать | CVE-2026-53668Эксплойта нет | React Router: Open redirect can lead to XSSshopify · react-router · CWE-79 | Средняя6,9 | — | 0,3 % | 27 июл. 2026 г. |
26Наблюдать | CVE-2025-68470Эксплойта нет | React Router has unexpected external redirect via untrusted pathsshopify · react-router · CWE-601 | Средняя6,5 | — | 0,5 % | 9 янв. 2026 г. |
26Наблюдать | CVE-2026-40181Эксплойта нет | React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretationshopify · react-router · CWE-601 | Средняя6,6 | — | 0,3 % | 2 июн. 2026 г. |
26Наблюдать | CVE-2026-22030Эксплойта нет | React Router has CSRF issue in Action/Server Action Request Processingshopify · react-router · CWE-346 | Средняя6,5 | — | 0,2 % | 9 янв. 2026 г. |
25Наблюдать | CVE-2026-39862Эксплойта нет | Tophat has a Command Injection Vulnerability When Accessing a Maliciously Crafted Tophat Linkshopify · tophat · CWE-78 | Средняя6,3 | — | 1,1 % | 8 апр. 2026 г. |
24Наблюдать | CVE-2020-8176Эксплойта нет | A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shopshopify · koa-shopify-auth · CWE-79 | Средняя6,1 | — | 1,0 % | 2 июл. 2020 г. |
24Наблюдать | CVE-2026-22029Эксплойта нет | React Router vulnerable to XSS via Open Redirectsshopify · remix-run\/react · CWE-79 | Средняя6,1 | — | 0,9 % | 9 янв. 2026 г. |
24Наблюдать | CVE-2026-53666Эксплойта нет | React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydrationshopify · react-router · CWE-470 | Средняя6,1 | — | 0,4 % | 27 июл. 2026 г. |
24Наблюдать | CVE-2026-53667Эксплойта нет | React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667)shopify · react-router · CWE-79 | Средняя6,1 | — | 0,4 % | 27 июл. 2026 г. |
21Наблюдать | CVE-2022-29230Эксплойта нет | Potential cross-site scripting (XSS) vulnerability in Hydrogenshopify · hydrogen · CWE-79 | Средняя5,4 | — | 0,8 % | 18 мая 2022 г. |
21Наблюдать | CVE-2026-33244Эксплойта нет | React Router has stored XSS via unescaped Location header in prerendered redirect HTMLshopify · react-router · CWE-79 | Средняя5,4 | — | 0,1 % | 2 июн. 2026 г. |
20Наблюдать | CVE-2026-53669Эксплойта нет | React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)shopify · react-router · CWE-601 | Средняя5,1 | — | 0,3 % | 27 июл. 2026 г. |
18Наблюдать | CVE-2026-33245Эксплойта нет | React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targetsshopify · react-router · CWE-79 | Средняя4,7 | — | 0,2 % | 2 июн. 2026 г. |
- CVE-2025-6168641В плане
React Router has Path Traversal in File Session Storage
КритическаяCVSS 9,1Proof of conceptEPSS 18 %shopify · react-router\/node9 янв. 2026 г.
- CVE-2026-5568534Наблюдать
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %shopify · react-router27 июл. 2026 г.
- CVE-2026-4221132Наблюдать
React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %shopify · react-router2 июн. 2026 г.
- CVE-2026-2188432Наблюдать
React Router SSR XSS in ScrollRestoration
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %shopify · react-router9 янв. 2026 г.
- CVE-2025-5905730Наблюдать
React Router has XSS Vulnerability
ВысокаяCVSS 7,6Proof of conceptEPSS 1 %shopify · react-router9 янв. 2026 г.
- CVE-2026-4234230Наблюдать
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %shopify · react-router2 июн. 2026 г.
- CVE-2026-3407730Наблюдать
React Router vulnerable to Denial of Service via reflected user input in single-fetch
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %shopify · react-router2 июн. 2026 г.
- CVE-2026-3406028Наблюдать
Ruby LSP has arbitrary code execution through branch setting
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %shopify · ruby lsp30 мар. 2026 г.
- CVE-2026-5366827Наблюдать
React Router: Open redirect can lead to XSS
СредняяCVSS 6,9Эксплойта нетEPSS 0 %shopify · react-router27 июл. 2026 г.
- CVE-2025-6847026Наблюдать
React Router has unexpected external redirect via untrusted paths
СредняяCVSS 6,5Эксплойта нетEPSS 1 %shopify · react-router9 янв. 2026 г.
- CVE-2026-4018126Наблюдать
React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation
СредняяCVSS 6,6Эксплойта нетEPSS 0 %shopify · react-router2 июн. 2026 г.
- CVE-2026-2203026Наблюдать
React Router has CSRF issue in Action/Server Action Request Processing
СредняяCVSS 6,5Эксплойта нетEPSS 0 %shopify · react-router9 янв. 2026 г.
- CVE-2026-3986225Наблюдать
Tophat has a Command Injection Vulnerability When Accessing a Maliciously Crafted Tophat Link
СредняяCVSS 6,3Эксплойта нетEPSS 1 %shopify · tophat8 апр. 2026 г.
- CVE-2020-817624Наблюдать
A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop
СредняяCVSS 6,1Эксплойта нетEPSS 1 %shopify · koa-shopify-auth2 июл. 2020 г.
- CVE-2026-2202924Наблюдать
React Router vulnerable to XSS via Open Redirects
СредняяCVSS 6,1Эксплойта нетEPSS 1 %shopify · remix-run\/react9 янв. 2026 г.
- CVE-2026-5366624Наблюдать
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
СредняяCVSS 6,1Эксплойта нетEPSS 0 %shopify · react-router27 июл. 2026 г.
- CVE-2026-5366724Наблюдать
React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %shopify · react-router27 июл. 2026 г.
- CVE-2022-2923021Наблюдать
Potential cross-site scripting (XSS) vulnerability in Hydrogen
СредняяCVSS 5,4Эксплойта нетEPSS 1 %shopify · hydrogen18 мая 2022 г.
- CVE-2026-3324421Наблюдать
React Router has stored XSS via unescaped Location header in prerendered redirect HTML
СредняяCVSS 5,4Эксплойта нетEPSS 0 %shopify · react-router2 июн. 2026 г.
- CVE-2026-5366920Наблюдать
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
СредняяCVSS 5,1Эксплойта нетEPSS 0 %shopify · react-router27 июл. 2026 г.
- CVE-2026-3324518Наблюдать
React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets
СредняяCVSS 4,7Эксплойта нетEPSS 0 %shopify · react-router2 июн. 2026 г.