Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Discounts/DiscountCalculator.php and vendor/shopper/cart/src/Pipelines/Calculate.php without enforcing a positive-value invariant. Because the calculation subtracts discountTotal from the subtotal, a negative discount increases the resulting order total instead of reducing it. Malformed discount records can therefore cause incorrect pricing and financial data integrity failures, although the advisory does not establish a customer-facing exploitation path. This issue is fixed in version 2.9.0.
References
Configurations
No configuration.
History
16 Sep 2026, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/shopperlabs/shopper/security/advisories/GHSA-5vf4-452p-jjhf - |
Information
Published : 2026-09-15 18:17
Updated : 2026-09-16 15:17
NVD link : CVE-2026-56831
Mitre link : CVE-2026-56831
CVE.ORG link : CVE-2026-56831
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
