CVE Tools

Shopify

6 CVEs tracked since 2026. Since Jan 2026, none of them reached CISA KEV.

Shopify CVEs per month

Jan 2026 to Jan 2026. Point at a month, or focus the strip and use the arrow keys.
Shopify CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-0160

Products

The products that kept showing up in Shopify's monthly top three, with their CVEs summed over those months.

  1. React-router51 month
  2. Remix-run\/react41 month
  3. React-router\/node11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Shopify.

  1. CVE-2026-48122Workspace settings can override executable and Gemfile paths used by the Ruby LSP VS Code extension—
  2. CVE-2026-53669React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)6.1
  3. CVE-2026-55685React Router: Unauthenticated Denial of Service via Inefficient Route Matching7.5
  4. CVE-2026-53668React Router: Open redirect can lead to XSS6.9
  5. CVE-2026-53667React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667)6.9
  6. CVE-2026-53666React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration6.1
  7. CVE-2026-42342React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint7.5
  8. CVE-2026-42211React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE8.1
  9. CVE-2026-40181React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation6.1
  10. CVE-2026-34077React Router vulnerable to Denial of Service via reflected user input in single-fetch7.5
  11. CVE-2026-33245React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets8.0
  12. CVE-2026-33244React Router has stored XSS via unescaped Location header in prerendered redirect HTML5.4
  13. CVE-2026-39862Tophat has a Command Injection Vulnerability When Accessing a Maliciously Crafted Tophat Link8.8
  14. CVE-2026-34060Ruby LSP has arbitrary code execution through branch setting9.8
  15. CVE-2026-22030React Router has CSRF issue in Action/Server Action Request Processing6.5

The record

Peak rank
#160 in Jan 2026
Busiest month shown
Jan 2026, 6 CVEs
Months with a KEV entry
0 since Jan 2026
Monthly snapshots
1 since 2026
Shopify's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store