Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Shopify

First CVE: Jul 2, 2020Active for: 6 yearsTotal CVEs: 16
27.2
VTI Score
Low

Shopify's vulnerability footprint centers on a focused set of open-source web frameworks and development libraries, including React Router and Remix, that power e-commerce and web applications across a broad user base. These disclosures skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including cross-site scripting, open redirects, resource exhaustion, cross-site request forgery, and deserialization flaws that are characteristic of web request handling and routing layers. Defenders should monitor this vendor's security advisories for upstream dependencies in their web infrastructure, particularly for internet-facing storefronts and authentication boundaries; current severity and exploitation metrics are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Shopify over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 2, 2020
6 years ago
Most Recent CVE
Jun 2, 2026
53 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-61686CRITICAL
React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if cre
Jan 10, 20269.146NONO
CVE-2026-42211HIGH
React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution (
Jun 2, 20268.136NONO
CVE-2026-39862HIGH
Tophat is a mobile applications testing harness. Prior to 2.5.1, Tophat is affected by remote code execution via crafted tophat:// or http://localhost:29070 URLs. The arguments que
Apr 8, 20268.836NONO
CVE-2026-34077HIGH
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-
Jun 2, 20267.533NONO
CVE-2026-42342HIGH
React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can c
Jun 2, 20267.532NONO
CVE-2026-34060CRITICAL
Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rubyLsp.branch VS Code workspace s
Mar 31, 20269.831NONO
CVE-2026-21884HIGH
React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollResto
Jan 10, 20268.231NONO
CVE-2025-59057HIGH
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router
Jan 10, 20267.630NONO
CVE-2026-22029MEDIUM
React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects
Jan 10, 20266.127NONO
CVE-2026-40181MEDIUM
React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger an open redirect to an exter
Jun 2, 20266.126NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
50%
38%
13%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (87.5%)
High2 (12.5%)
Unknown0 (0.0%)
User Interaction
None7 (43.8%)
Unknown0 (0.0%)
Required9 (56.3%)
Privileges Required
Low5 (31.3%)
High0 (0.0%)
None11 (68.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Shopify.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Shopify — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Shopify's Products

View all 2 CNAs →

Top CWEs