VendorsShopifykoa-shopify-authall versions
Vulnerabilities

Shopify koa-shopify-auth

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2020-8176
A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop` parameter on the `/shopify/auth/enable_cookies` endpoint.
Published 2020-07-02 · Modified
6.1EPSS 0.010