Vulnerabilities (CVE)

Filtered by vendor Shopify Subscribe
Filtered by product Koa-shopify-auth
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8176 1 Shopify 1 Koa-shopify-auth 2024-02-28 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop` parameter on the `/shopify/auth/enable_cookies` endpoint.