Shopify's vulnerability footprint centers on a focused set of open-source web frameworks and development libraries, including React Router and Remix, that power e-commerce and web applications across a broad user base. These disclosures skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including cross-site scripting, open redirects, resource exhaustion, cross-site request forgery, and deserialization flaws that are characteristic of web request handling and routing layers. Defenders should monitor this vendor's security advisories for upstream dependencies in their web infrastructure, particularly for internet-facing storefronts and authentication boundaries; current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shopify over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-61686CRITICAL React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if cre | Jan 10, 2026 | 9.1 | 46 | NO | NO |
CVE-2026-42211HIGH React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution ( | Jun 2, 2026 | 8.1 | 36 | NO | NO |
CVE-2026-39862HIGH Tophat is a mobile applications testing harness. Prior to 2.5.1, Tophat is affected by remote code execution via crafted tophat:// or http://localhost:29070 URLs. The arguments que | Apr 8, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-34077HIGH React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross- | Jun 2, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-42342HIGH React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can c | Jun 2, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-34060CRITICAL Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rubyLsp.branch VS Code workspace s | Mar 31, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-21884HIGH React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollResto | Jan 10, 2026 | 8.2 | 31 | NO | NO |
CVE-2025-59057HIGH React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router | Jan 10, 2026 | 7.6 | 30 | NO | NO |
CVE-2026-22029MEDIUM React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects | Jan 10, 2026 | 6.1 | 27 | NO | NO |
CVE-2026-40181MEDIUM React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger an open redirect to an exter | Jun 2, 2026 | 6.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shopify.
Media articles that mention a CVE ID that affects a product developed by Shopify — matched by CVE ID, not by vendor name.