By combining AI with human insight, Armis Vulnerability Intelligence Database offers extended coverage for vulnerabilities that matter to you, your industry, and provides you with clear remediation instructions.
Loading CVE list…
CVE Name
Severity Score
Published Date
CISA KEV
New from Armis
Armis Pulse
One CVE. Every day. Curated by Armis researchers and delivered to your inbox or RSS reader.
See everything.Identify true risk.Proactively mitigate threats.Book a Demo
Let's talk!
CVE-2026-47743:
Loading CVE details…
CVE-2026-47743 | High Severity | Armis
CVE-2026-47743:
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent model identifiers as public properties without the #[Locked] attribute. An authenticated user could rewrite the wire payload from the browser to target any record id, bypassing the implicit scoping enforced by the page routing. Second, Customers/Create::store() re-passed a Hidden_password form field straight into the create payload. The plaintext password was rendered into the HTML and transported through the Livewire snapshot in clear text, exposing credentials in the page DOM and in any logging that captures Livewire payloads. Finally, the product barcode field was rendered through DNS1DFacade::getBarcodeHTML() with {!! !!}. An attacker with edit_products permission could persist malicious payload in the barcode field that would execute in the browser of any admin user viewing that product, enabling session theft and privileged-action chaining. Starting in v2.8.0, all vulnerable Livewire model identifiers are now marked #[Locked]; Customers/Create no longer round-trips the password through a Hidden form field; the plaintext password is hashed at action boundary and never returned to the client; and the product barcode rendering now escapes the value before passing it to the barcode generator and the output is wrapped in an <svg> context that does not interpret event handlers. No known workarounds are available.
Score
A numerical rating that indicates how dangerous this vulnerability is.
8.7High
Published Date:Jul 23, 2026
CISA KEV Date:*No Data*
Industries Affected:20
Threat Predictions
EPSS Score:0.4
EPSS Percentile:28%
Exploitability
Score:2.3
Attack Vector:NETWORK
Attack Complexity:LOW
Privileges Required:LOW
User Interaction:REQUIRED
Scope:CHANGED
Impact
Score:5.8
Confidentiality Impact:HIGH
Integrity Impact:HIGH
Availability Impact:NONE
Description Preview
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent model identifiers as public properties without the #[Locked] attribute. An authenticated user could rewrite the wire payload from the browser to target any record id, bypassing the implicit scoping enforced by the page routing. Second, Customers/Create::store() re-passed a Hidden_password form field straight into the create payload. The plaintext password was rendered into the HTML and transported through the Livewire snapshot in clear text, exposing credentials in the page DOM and in any logging that captures Livewire payloads. Finally, the product barcode field was rendered through DNS1DFacade::getBarcodeHTML() with {!! !!}. An attacker with edit_products permission could persist malicious payload in the barcode field that would execute in the browser of any admin user viewing that product, enabling session theft and privileged-action chaining. Starting in v2.8.0, all vulnerable Livewire model identifiers are now marked #[Locked]; Customers/Create no longer round-trips the password through a Hidden form field; the plaintext password is hashed at action boundary and never returned to the client; and the product barcode rendering now escapes the value before passing it to the barcode generator and the output is wrapped in an <svg> context that does not interpret event handlers. No known workarounds are available.
Industries Affected
Below is a list of industries most commonly impacted or potentially at risk based on intelligence.
Low
Mining
Utilities
Information
Construction
Retail Trade
Manufacturing
Wholesale Trade
Educational Services
Finance and Insurance
Public Administration
Real Estate Rental and Leasing
Transportation and Warehousing
Accommodation and Food Services
Health Care and Social Assistance
Arts, Entertainment, and Recreation
Management of Companies and Enterprises
Agriculture, Forestry, Fishing and Hunting
Other Services (except Public Administration)
Professional, Scientific, and Technical Services
Administrative and Support and Waste Management and Remediation Services