shopify kayıtları
shopify üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-400 Uncontrolled Resource Consumption2
- CWE-502 Deserialization of Untrusted Data1
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2025-61686Kavram kanıtı | React Router has Path Traversal in File Session Storageshopify · react-router\/node · CWE-22 | Kritik9,1 | — | %17,6 | 9 Oca 2026 |
34İzleyin | CVE-2026-55685İstismar yok | React Router: Unauthenticated Denial of Service via Inefficient Route Matchingshopify · react-router · CWE-400 | Yüksek8,7 | — | %0,7 | 27 Tem 2026 |
32İzleyin | CVE-2026-42211İstismar yok | React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCEshopify · react-router · CWE-502 | Yüksek8,1 | — | %0,6 | 2 Haz 2026 |
32İzleyin | CVE-2026-21884İstismar yok | React Router SSR XSS in ScrollRestorationshopify · react-router · CWE-79 | Yüksek8,2 | — | %0,5 | 9 Oca 2026 |
30İzleyin | CVE-2025-59057Kavram kanıtı | React Router has XSS Vulnerabilityshopify · react-router · CWE-79 | Yüksek7,6 | — | %0,5 | 9 Oca 2026 |
30İzleyin | CVE-2026-42342İstismar yok | React Router vulnerable to DoS via unbounded path expansion in __manifest endpointshopify · react-router · CWE-400 | Yüksek7,5 | — | %0,5 | 2 Haz 2026 |
30İzleyin | CVE-2026-34077İstismar yok | React Router vulnerable to Denial of Service via reflected user input in single-fetchshopify · react-router · CWE-770 | Yüksek7,5 | — | %0,5 | 2 Haz 2026 |
28İzleyin | CVE-2026-34060İstismar yok | Ruby LSP has arbitrary code execution through branch settingshopify · ruby lsp · CWE-94 | Yüksek7,1 | — | %0,6 | 30 Mar 2026 |
27İzleyin | CVE-2026-53668İstismar yok | React Router: Open redirect can lead to XSSshopify · react-router · CWE-79 | Orta6,9 | — | %0,3 | 27 Tem 2026 |
26İzleyin | CVE-2025-68470İstismar yok | React Router has unexpected external redirect via untrusted pathsshopify · react-router · CWE-601 | Orta6,5 | — | %0,5 | 9 Oca 2026 |
26İzleyin | CVE-2026-40181İstismar yok | React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretationshopify · react-router · CWE-601 | Orta6,6 | — | %0,3 | 2 Haz 2026 |
26İzleyin | CVE-2026-22030İstismar yok | React Router has CSRF issue in Action/Server Action Request Processingshopify · react-router · CWE-346 | Orta6,5 | — | %0,2 | 9 Oca 2026 |
25İzleyin | CVE-2026-39862İstismar yok | Tophat has a Command Injection Vulnerability When Accessing a Maliciously Crafted Tophat Linkshopify · tophat · CWE-78 | Orta6,3 | — | %1,1 | 8 Nis 2026 |
24İzleyin | CVE-2020-8176İstismar yok | A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shopshopify · koa-shopify-auth · CWE-79 | Orta6,1 | — | %1,0 | 2 Tem 2020 |
24İzleyin | CVE-2026-22029İstismar yok | React Router vulnerable to XSS via Open Redirectsshopify · remix-run\/react · CWE-79 | Orta6,1 | — | %0,9 | 9 Oca 2026 |
24İzleyin | CVE-2026-53666İstismar yok | React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydrationshopify · react-router · CWE-470 | Orta6,1 | — | %0,4 | 27 Tem 2026 |
24İzleyin | CVE-2026-53667İstismar yok | React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667)shopify · react-router · CWE-79 | Orta6,1 | — | %0,4 | 27 Tem 2026 |
21İzleyin | CVE-2022-29230İstismar yok | Potential cross-site scripting (XSS) vulnerability in Hydrogenshopify · hydrogen · CWE-79 | Orta5,4 | — | %0,8 | 18 May 2022 |
21İzleyin | CVE-2026-33244İstismar yok | React Router has stored XSS via unescaped Location header in prerendered redirect HTMLshopify · react-router · CWE-79 | Orta5,4 | — | %0,1 | 2 Haz 2026 |
20İzleyin | CVE-2026-53669İstismar yok | React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)shopify · react-router · CWE-601 | Orta5,1 | — | %0,3 | 27 Tem 2026 |
18İzleyin | CVE-2026-33245İstismar yok | React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targetsshopify · react-router · CWE-79 | Orta4,7 | — | %0,2 | 2 Haz 2026 |
- CVE-2025-6168641Planlayın
React Router has Path Traversal in File Session Storage
KritikCVSS 9,1Kavram kanıtıEPSS %18shopify · react-router\/node9 Oca 2026
- CVE-2026-5568534İzleyin
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
YüksekCVSS 8,7İstismar yokEPSS %1shopify · react-router27 Tem 2026
- CVE-2026-4221132İzleyin
React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
YüksekCVSS 8,1İstismar yokEPSS %1shopify · react-router2 Haz 2026
- CVE-2026-2188432İzleyin
React Router SSR XSS in ScrollRestoration
YüksekCVSS 8,2İstismar yokEPSS %1shopify · react-router9 Oca 2026
- CVE-2025-5905730İzleyin
React Router has XSS Vulnerability
YüksekCVSS 7,6Kavram kanıtıEPSS %1shopify · react-router9 Oca 2026
- CVE-2026-4234230İzleyin
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
YüksekCVSS 7,5İstismar yokEPSS %0shopify · react-router2 Haz 2026
- CVE-2026-3407730İzleyin
React Router vulnerable to Denial of Service via reflected user input in single-fetch
YüksekCVSS 7,5İstismar yokEPSS %0shopify · react-router2 Haz 2026
- CVE-2026-3406028İzleyin
Ruby LSP has arbitrary code execution through branch setting
YüksekCVSS 7,1İstismar yokEPSS %1shopify · ruby lsp30 Mar 2026
- CVE-2026-5366827İzleyin
React Router: Open redirect can lead to XSS
OrtaCVSS 6,9İstismar yokEPSS %0shopify · react-router27 Tem 2026
- CVE-2025-6847026İzleyin
React Router has unexpected external redirect via untrusted paths
OrtaCVSS 6,5İstismar yokEPSS %1shopify · react-router9 Oca 2026
- CVE-2026-4018126İzleyin
React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation
OrtaCVSS 6,6İstismar yokEPSS %0shopify · react-router2 Haz 2026
- CVE-2026-2203026İzleyin
React Router has CSRF issue in Action/Server Action Request Processing
OrtaCVSS 6,5İstismar yokEPSS %0shopify · react-router9 Oca 2026
- CVE-2026-3986225İzleyin
Tophat has a Command Injection Vulnerability When Accessing a Maliciously Crafted Tophat Link
OrtaCVSS 6,3İstismar yokEPSS %1shopify · tophat8 Nis 2026
- CVE-2020-817624İzleyin
A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop
OrtaCVSS 6,1İstismar yokEPSS %1shopify · koa-shopify-auth2 Tem 2020
- CVE-2026-2202924İzleyin
React Router vulnerable to XSS via Open Redirects
OrtaCVSS 6,1İstismar yokEPSS %1shopify · remix-run\/react9 Oca 2026
- CVE-2026-5366624İzleyin
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
OrtaCVSS 6,1İstismar yokEPSS %0shopify · react-router27 Tem 2026
- CVE-2026-5366724İzleyin
React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667)
OrtaCVSS 6,1İstismar yokEPSS %0shopify · react-router27 Tem 2026
- CVE-2022-2923021İzleyin
Potential cross-site scripting (XSS) vulnerability in Hydrogen
OrtaCVSS 5,4İstismar yokEPSS %1shopify · hydrogen18 May 2022
- CVE-2026-3324421İzleyin
React Router has stored XSS via unescaped Location header in prerendered redirect HTML
OrtaCVSS 5,4İstismar yokEPSS %0shopify · react-router2 Haz 2026
- CVE-2026-5366920İzleyin
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
OrtaCVSS 5,1İstismar yokEPSS %0shopify · react-router27 Tem 2026
- CVE-2026-3324518İzleyin
React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets
OrtaCVSS 4,7İstismar yokEPSS %0shopify · react-router2 Haz 2026