CVE-2026-47741

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Under concurrent checkout pressure (Black Friday, flash sale, viral coupon), the global usage_limit was silently exceeded: orders were committed with the discount fully applied to price_amount while the counter blocked at usage_limit. The merchant had no signal that an over-redemption had occurred. This vulnerability is fixed in 2.8.0.
Configurations

No configuration.

History

22 Jul 2026, 06:10

Type Values Removed Values Added
Summary
  • (es) Shopper es un Panel de Administración de e-commerce Headless. Antes de la versión 2.8.0, CreateOrderFromCartAction::execute creaba previamente la fila de la Orden antes de verificar e incrementar el contador total_use del descuento. Bajo presión de pago concurrente (Black Friday, venta flash, cupón viral), el usage_limit global se excedía silenciosamente: las órdenes se confirmaban con el descuento aplicado completamente al price_amount mientras el contador se bloqueaba en el usage_limit. El comerciante no tenía ninguna señal de que se había producido una sobre-redención. Esta vulnerabilidad está corregida en la versión 2.8.0.

29 May 2026, 20:16

Type Values Removed Values Added
References () https://github.com/shopperlabs/shopper/issues/510 - () https://github.com/shopperlabs/shopper/issues/510 -

29 May 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 19:16

Updated : 2026-07-22 06:10


NVD link : CVE-2026-47741

Mitre link : CVE-2026-47741

CVE.ORG link : CVE-2026-47741


JSON object : View

Products Affected

No product.

CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')