Description
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Discounts/DiscountCalculator.php and vendor/shopper/cart/src/Pipelines/Calculate.php without enforcing a positive-value invariant. Because the calculation subtracts discountTotal from the subtotal, a negative discount increases the resulting order total instead of reducing it. Malformed discount records can therefore cause incorrect pricing and financial data integrity failures, although the advisory does not establish a customer-facing exploitation path. This issue is fixed in version 2.9.0.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Financial Data Integrity
Action: Immediate Patch
AI Analysis

Impact

Shopper, a headless e‑commerce administration interface, allows administrators to enter fixed‑amount discounts with negative values through its cpanel/discounts page. These values are persisted without validation and are subsequently used by the order calculation pipeline. Since the pipeline subtracts the discount amount from the subtotal, a negative discount inflates the order total rather than reducing it. The vulnerability is a classic input validation weakness (CWE‑20). It does not provide a direct code execution or denial‑of‑service capability, but it can lead to incorrect pricing and financial data integrity failures for each order that consumes a negative discount.

Affected Systems

All ShopperLabs Shopper releases prior to version 2.9.0 are affected. The product is the Headless e‑commerce Admin Panel published by ShopperLabs. Any installation using a pre‑2.9.0 build that has not applied the 2.9.0 fix and that retains the administrative discounts interface is potentially vulnerable.

Risk and Exploitability

The base CVSS score of 6.5 reflects moderate severity; the EPSS score of less than 1 % indicates a very low likelihood of exploitation, and it is not listed in the CISA KEV catalog. Based on the description, exploitation requires authenticated access to the administrative discounts page. Once a negative discount record is created, the application processes it unconditionally, yielding inflated totals. Because the flaw resides in a non‑publicly accessible interface and does not provide arbitrary code execution, the overall risk is confined to potential financial loss rather than broader system compromise.

Generated by OpenCVE AI on September 20, 2026 at 14:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Shopper to version 2.9.0 or later, where negative‑discount values are validated and rejected.
  • Audit the database for existing sh_discounts entries with negative fixed_amount values and correct them, setting the amount to zero or a valid positive value.
  • Restrict creation of new discount records to users with the highest administrative privileges or temporarily disable the discounts feature until the audit and upgrade are processed using a negative discount and update accounting records to rectify the financial discrepancy.

Generated by OpenCVE AI on September 20, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5vf4-452p-jjhf Shopper: Negative discount values accepted and propagated through order calculation pipeline
History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Shopperlabs
Shopperlabs shopper
Vendors & Products Shopperlabs
Shopperlabs shopper

Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Discounts/DiscountCalculator.php and vendor/shopper/cart/src/Pipelines/Calculate.php without enforcing a positive-value invariant. Because the calculation subtracts discountTotal from the subtotal, a negative discount increases the resulting order total instead of reducing it. Malformed discount records can therefore cause incorrect pricing and financial data integrity failures, although the advisory does not establish a customer-facing exploitation path. This issue is fixed in version 2.9.0.
Title Shopper: Negative discount values accepted and propagated through order calculation pipeline
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Shopperlabs Shopper
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T14:41:52.114Z

Reserved: 2026-06-23T14:55:09.117Z

Link: CVE-2026-56831

cve-icon Vulnrichment

Updated: 2026-09-16T14:41:33.248Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:25.213

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-56831

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:45:06Z

Weaknesses
  • CWE-20

    Improper Input Validation