What is CVE-2026-47743?
Prior to version 2.8.0 of the Shopper headless e-commerce admin panel, multiple admin Livewire components contained vulnerabilities allowing data tampering, sensitive data disclosure, and stored XSS due to exposed Eloquent model identifiers. Authenticated attackers could exploit these flaws to perform unauthorized actions. Upgrading to version 2.8.0 or later is strongly recommended.
Azərbaycanca: Shopper headless e-ticarət admin panelində, 2.8.0 versiyasından əvvəl admin Livewire komponentlərində data manipulyasiyası, həssas məlumatların ifşası və saxlanılan XSS zəiflikləri aşkar edilib. Bu qüsurlar autentifikasiya olunmuş istifadəçilərə identifikatorları manipulyasiya edərək icazəsiz əməliyyatlar aparmağa imkan verir. Dərhal 2.8.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What types of attacks can CVE-2026-47743 be exploited for?
This vulnerability allows authenticated users to perform data tampering, sensitive data disclosure, and stored XSS attacks.
To which version should the Shopper admin panel be upgraded to fix CVE-2026-47743?
It is recommended to upgrade the Shopper headless e-commerce admin panel to version 2.8.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.