TOPSHOPIFY.md

July 18, 2026 · View on GitHub

Top reports from Shopify program at HackerOne:

  1. Takeover an account that doesn't have a Shopify ID and more to Shopify - 2991 upvotes, $0
  2. Email Confirmation Bypass in myshop.myshopify.com that Leads to Full Privilege Escalation to Any Shop Owner by Taking Advantage of the Shopify SSO to Shopify - 1913 upvotes, $0
  3. Github access token exposure to Shopify - 1544 upvotes, $50000
  4. [Part II] Email Confirmation Bypass in myshop.myshopify.com that Leads to Full Privilege Escalation to Shopify - 894 upvotes, $0
  5. H1514 Remote Code Execution on kitcrm using bulk customer update of Priority Products to Shopify - 830 upvotes, $0
  6. SSRF in Exchange leads to ROOT access in all instances to Shopify - 577 upvotes, $0
  7. Email Confirmation Bypass in your-store.myshopify.com which leads to privilege escalation to Shopify - 559 upvotes, $0
  8. Shopify Stocky App OAuth Misconfiguration to Shopify - 525 upvotes, $0
  9. H1514 Server Side Template Injection in Return Magic email templates? to Shopify - 408 upvotes, $0
  10. H1514 Ability to MiTM Shopify PoS Session to Takeover Communications to Shopify - 372 upvotes, $0
  11. XSS while logging using Google to Shopify - 341 upvotes, $1750
  12. Stored XSS in my staff name fired in another your internal panel to Shopify - 325 upvotes, $0
  13. Able to Takeover Merchants Accounts Even They Have Already Setup SSO, After Bypassing the Email Confirmation to Shopify - 310 upvotes, $0
  14. Shopify admin authentication bypass using partners.shopify.com to Shopify - 309 upvotes, $0
  15. CSRF on connecting Paypal as Payment Provider to Shopify - 303 upvotes, $0
  16. Ability to bypass partner email confirmation to take over any store given an employee email to Shopify - 270 upvotes, $15250
  17. DoS Vulnerability via Cache Poisoning on cdn.shopify.com and shopify-assets.shopifycdn.com to Shopify - 262 upvotes, $3800
  18. XSS at jamfpro.shopifycloud.com to Shopify - 239 upvotes, $9400
  19. Shopify Partners Invitation Process Allows Privilege Escalation Without Email Verification to Shopify - 239 upvotes, $3500
  20. H1514 DOMXSS on Embedded SDK via Shopify.API.setWindowLocation abusing cookie Stuffing to Shopify - 195 upvotes, $0
  21. H1514 [*.(my)shopify.com] - Viewing Password Protected Content to Shopify - 192 upvotes, $3000
  22. IDOR on GraphQL queries BillingDocumentDownload and BillDetails to Shopify - 180 upvotes, $5000
  23. Limited Privilege User Can Create Unauthorized Referrals on partners.shopify.com to Shopify - 179 upvotes, $0
  24. XSS at https://exchangemarketplace.com/blogsearch to Shopify - 174 upvotes, $0
  25. GraphQL AdminGenerateSessionPayload is leaked to staff with no permission to Shopify - 173 upvotes, $0
  26. [h1-2102] FQDN takeover on all Shopify wholesale customer domains by trailing dot (RFC 1034) to Shopify - 166 upvotes, $3100
  27. XSS in www.shopify.com/markets?utm_source= to Shopify - 159 upvotes, $0
  28. Undocumented fileCopy GraphQL API to Shopify - 157 upvotes, $2000
  29. Session works after logout from Shopify account and password of online store is displayed to Shopify - 157 upvotes, $0
  30. Stored XSS in SVG file as data: url to Shopify - 150 upvotes, $5300
  31. Informations disclosure - Access to some checkout informations to Shopify - 148 upvotes, $0
  32. User with removed manage shops permissions is still able to make changes to a shop to Shopify - 145 upvotes, $0
  33. H1514 Session Fixation on multiple shopify-built apps on *.shopifycloud.com and *.shopifyapps.com to Shopify - 144 upvotes, $0
  34. HTTP Response Header Injection in shopify/pitchfork + Rack 3 to Shopify - 136 upvotes, $800
  35. [Information Disclosure] Amazon S3 Bucket of Shopify Ping (iOS) have public access of other users image to Shopify - 134 upvotes, $2900
  36. Create free Shopify application credits. to Shopify - 133 upvotes, $0
  37. Reflected XSS In Marketing Reports Page On *.myshopify.com/admin to Shopify - 128 upvotes, $0
  38. Stored XSS in private message to Shopify - 124 upvotes, $1000
  39. XSS on any Shopify shop via abuse of the HTML5 structured clone algorithm in postMessage listener on "/:id/digital_wallets/dialog" to Shopify - 121 upvotes, $3000
  40. Disclose Any Store products, Files, Purchase Orders Via Email through Shopify Stocky APP to Shopify - 116 upvotes, $0
  41. Access to Employee calendar disclosing internal presentation and meetings to Shopify - 111 upvotes, $1000
  42. Account Takeover Vulnerability in Shopify Collabs Platform Due to Missing Email Verification to Shopify - 111 upvotes, $800
  43. Admin panel Exposure without credential at https://plus-website.shopifycloud.com/admin.php to Shopify - 109 upvotes, $2900
  44. Reflected XSS on help.shopify.com to Shopify - 109 upvotes, $500
  45. Stored XSS in Shopify Chat to Shopify - 106 upvotes, $500
  46. Reflected XSS in *.myshopify.com/account/register to Shopify - 104 upvotes, $0
  47. Bypass a fix for report #708013 to Shopify - 102 upvotes, $3500
  48. Exposed Cortex API at https://cortex-ingest.shopifycloud.com/ to Shopify - 98 upvotes, $6300
  49. Reflected XSS online-store-git.shopifycloud.com to Shopify - 98 upvotes, $3500
  50. Ability to publish a paid theme without purchasing it. to Shopify - 90 upvotes, $2000
  51. Reverse Proxy misroute leading to steal X-Shopify-Access-Token header to Shopify - 88 upvotes, $1000
  52. Bypass of biometrics security functionality is possible in Android application (com.shopify.mobile) to Shopify - 88 upvotes, $500
  53. Add new development stores without permission to Shopify - 88 upvotes, $0
  54. XSS on shopshop.myshopify.com/admin/ and partners.shopify.com via whitelist bypass in SVG icon for sales channel applications to Shopify - 86 upvotes, $5000
  55. No Session Expiry after log-out, attacker can reuse the old cookies to Shopify - 86 upvotes, $500
  56. Ability to link a Google account to another staff account/store owner that isn't linked yet to Shopify - 84 upvotes, $0
  57. Reflected XSS in AI Chat Bot Greetings at help.shopify.com via Markdown Image Rendering to Shopify - 82 upvotes, $1600
  58. URL Path Manipulation Enables Cache Poisoning of Amazon Affiliate Products in Shopify Linkpop to Shopify - 82 upvotes, $500
  59. https://themes.shopify.com::: Host header web cache poisoning lead to DoS to Shopify - 81 upvotes, $2900
  60. SVG Server Side Request Forgery (SSRF) to Shopify - 80 upvotes, $500
  61. Reflective Cross-site Scripting via Newsletter Form to Shopify - 79 upvotes, $2000
  62. ██████ DOM XSS via Shopify.API.remoteRedirect to Shopify - 76 upvotes, $0
  63. Blog posts atom feed of a store with password protection can be accessed by anyone to Shopify - 76 upvotes, $0
  64. Exposure of shopify employee summit page allows anonymous user to place orders for free books to Shopify - 76 upvotes, $0
  65. Stored XSS in /admin/product and /admin/collections to Shopify - 75 upvotes, $5300
  66. Stored XSS in Discounts section to Shopify - 75 upvotes, $1000
  67. Ability to verify any email address you don't own - accounts.shopify.com to Shopify - 75 upvotes, $0
  68. xss stored to Shopify - 75 upvotes, $0
  69. CircleCI token in github repo allows for access to sensitive build information to Shopify - 73 upvotes, $0
  70. Blind Stored XSS in shopify internal Parquet Viewer to Shopify - 73 upvotes, $0
  71. A staff member with no permissions can edit Store Customer Email to Shopify - 71 upvotes, $1500
  72. myshopify.com domain takeover to Shopify - 71 upvotes, $0
  73. help.shopify.com Cross Site Scripting to Shopify - 71 upvotes, $0
  74. Stealing livechat token and using it to chat as the user - user information disclosure to Shopify - 70 upvotes, $0
  75. Reflected XSS in <any>.myshopify.com through theme preview to Shopify - 69 upvotes, $0
  76. Session works after logout from Shopify account to Shopify - 69 upvotes, $0
  77. xss is triggered on your web to Shopify - 69 upvotes, $0
  78. POST-based XSS on apps.shopify.com to Shopify - 68 upvotes, $500
  79. Subdomain Takeover Via unclaimed Heroku Instance tim-exclusive.shopify.com to Shopify - 68 upvotes, $500
  80. Stored XSS through Facebook Page Connection to Shopify - 68 upvotes, $0
  81. A non-privileged user may create an admin account in Stocky to Shopify - 67 upvotes, $0
  82. Shopify GitHub Login and Password exposed all private source code might be available. to Shopify - 66 upvotes, $1500
  83. Cache poisoning via X-Forwarded-Host in www.shopify.com/partners/blog to Shopify - 66 upvotes, $1000
  84. Disclose customer orders details by shopify chat application. to Shopify - 65 upvotes, $2500
  85. Ability to Disable the Login Attempt of any Shopify Owner for 24 hrs (Zero_Click) to Shopify - 65 upvotes, $900
  86. URL Scheme Validation Bypass in Shopify Mobile App Allows Javascript Execution to Shopify - 65 upvotes, $0
  87. Staff without Manage Themes permissions can update themes to Shopify - 64 upvotes, $0
  88. admin.shopify.com: Shopify Flow continues sending internal emails to a configured recipient after the staff author is removed to Shopify - 64 upvotes, $0
  89. Xss triggered in Your-store.myshopify.com/admin/apps/shopify-email/editor/**** to Shopify - 63 upvotes, $2900
  90. Insufficient session expiration in the com.shopify.ping android app to Shopify - 63 upvotes, $0
  91. Session Persistence Designed to Keep Users Logged In Across Multiple Devices (Intended Behaviour) to Shopify - 63 upvotes, $0
  92. Using GraphQL, STAFF with NO explicit permissions on Store can retrieve Shopify Payments Balance. to Shopify - 62 upvotes, $500
  93. Unauthenticated access to Zendesk tickets through athena-flex-production.shopifycloud.com Okta bypass to Shopify - 61 upvotes, $0
  94. Open redirect using theme install to Shopify - 60 upvotes, $0
  95. Removing parts of URL from jQuery request exposes links for download of Paid Digital Assets of the most recent Order placed by anyone on the store! to Shopify - 58 upvotes, $2900
  96. Reflected XSS on AnyAny.myshopify.com/admin to Shopify - 58 upvotes, $1500
  97. H1514 [beerify.shopifycloud.com] GraphQL discloses internal beer consumption to Shopify - 57 upvotes, $802
  98. Non-store owners can transfer Shopify-managed domain to another domain provider to Shopify - 57 upvotes, $0
  99. SSRF in hatchful.shopify.com to Shopify - 56 upvotes, $500
  100. XSS Stored via Upload avatar PNG [HTML] File in accounts.shopify.com to Shopify - 56 upvotes, $0
  101. staff can able to extend shopify trial period without admin permission to Shopify - 56 upvotes, $0
  102. Stored XSS on activity to Shopify - 55 upvotes, $2000
  103. Self XSS to Shopify - 55 upvotes, $500
  104. authenticity token not verfied leads to change business name to Shopify - 54 upvotes, $1900
  105. Staff who only have apps and channels permission can do a takeover account at the wholesale store (Bypass get invitation link) to Shopify - 53 upvotes, $1600
  106. Unauthenticated read and write access to ALL endpoints of a store is possible for removed staff members who had "Apps" permission to Shopify - 53 upvotes, $0
  107. Stored xss to Shopify - 52 upvotes, $1000
  108. Stored XSS at https://linkpop.com to Shopify - 52 upvotes, $0
  109. Cross-site scripting on api.collabs.shopify.com to Shopify - 51 upvotes, $1600
  110. Inject page in admin panel via Shopify.API.pushState to Shopify - 51 upvotes, $500
  111. EC2 Takeover at turn.shopify.com to Shopify - 51 upvotes, $0
  112. [h1-2102] [Oberlo] Least privileged user can cancel account owner's subscription via POST on /payments/subscribe to Shopify - 51 upvotes, $0
  113. Bypass of fix #1370749 to Shopify - 50 upvotes, $900
  114. ability to install paid themes for free to Shopify - 50 upvotes, $0
  115. XSS within Shopify Email App - Admin to Shopify - 50 upvotes, $0
  116. Shopify.com Web Cache Deception vulnerability leads to personal information and CSRF tokens leakage to Shopify - 48 upvotes, $800
  117. Able to Login deactivated staff account in shopify app mobile to Shopify - 48 upvotes, $0
  118. apps.shopify.com - CSRF token leakage through Google Analytics to Shopify - 48 upvotes, $0
  119. Reflected XSS to Shopify - 48 upvotes, $0
  120. H1514 Bypass Wholesale account signup restrictions to Shopify - 48 upvotes, $0
  121. Stored XSS in blog comments through Shopify API to Shopify - 47 upvotes, $0
  122. Collaborators and Staff members without all necessary permissions are able to create, edit and install custom apps to Shopify - 46 upvotes, $1900
  123. xss stored in https://your store.myshopify.com/admin/ to Shopify - 46 upvotes, $1000
  124. [h1-2102] [Yaworski's Broskis] Low privilege user can read POS PINs via graphql and elevate his privilege to Shopify - 46 upvotes, $0
  125. H1514 DOM XSS on checkout.shopify.com via postMessage handler on /:id/sandbox/google_maps to Shopify - 45 upvotes, $500
  126. Subdomain Takeover - https://competition.shopify.com/ to Shopify - 45 upvotes, $0
  127. Blind Stored XSS Via Staff Name to Shopify - 44 upvotes, $3000
  128. XSS on services.shopify.com to Shopify - 43 upvotes, $500
  129. H1514 Removed Staff members who had "Apps" permission can still modify flow app connections to Shopify - 43 upvotes, $0
  130. Authentication Bypass on Icinga monitoring server to Shopify - 42 upvotes, $0
  131. Disclosure of Github Issues to Shopify - 41 upvotes, $0
  132. Exposed Slinky Instance Admin Panel to Shopify - 41 upvotes, $0
  133. Misconfiguration in Two Factor Authorisation to Shopify - 40 upvotes, $1500
  134. User sensitive information disclosure to Shopify - 40 upvotes, $1000
  135. Stored XSS on buy button to Shopify - 39 upvotes, $500
  136. Inject page in admin panel via Shopify.API.pushState with protocol invalid to Shopify - 39 upvotes, $500
  137. Potential to abuse pricing errors in saved carts to Shopify - 39 upvotes, $0
  138. App messaging can be hijacked by third-party websites to Shopify - 39 upvotes, $0
  139. Removed staff members who had "Manage shops" permission can still create development stores to Shopify - 38 upvotes, $0
  140. Low privileged user can create high privileged user's KITCRM authorization token and can read and write message to KIT to Shopify - 38 upvotes, $0
  141. Tinymce 2.4.0 to Shopify - 37 upvotes, $2000
  142. (BYPASS) Open redirect and XSS in supporthiring.shopify.com to Shopify - 37 upvotes, $0
  143. Replace other user files in Inbox messages to Shopify - 37 upvotes, $0
  144. StoreFront API allows for a brute force attack on customer login by not timing out ALL attempts to Shopify - 37 upvotes, $0
  145. Stored XSS on demo app link to Shopify - 37 upvotes, $0
  146. Low Privileged user can add or remove cash to/from sales register to Shopify - 37 upvotes, $0
  147. Race condition at create new Location to Shopify - 36 upvotes, $500
  148. Stored XSS in [shop].myshopify.com/admin/orders/[id] to Shopify - 36 upvotes, $0
  149. One Click XSS in [www.shopify.com] to Shopify - 36 upvotes, $0
  150. XSS on product comments in transfers to Shopify - 35 upvotes, $500
  151. Timeline Editor Self-XSS (Previous Fix #738072 Incomplete) to Shopify - 35 upvotes, $500
  152. Stored XSS Deleting Menu Links in the Shopify Admin to Shopify - 35 upvotes, $0
  153. XSS *.myshopify.com/collections/vendors?q= to Shopify - 35 upvotes, $0
  154. Unathorised access to admin endpoint on plus-website-staging5.shopifycloud.com to Shopify - 35 upvotes, $0
  155. mruby-engine: UAF in MRubyEngine#initialize enables local RCE to Shopify - 35 upvotes, $0
  156. Bypass Filter and get Stored Xss to Shopify - 34 upvotes, $3000
  157. [h1-2102] shopApps query from the graphql at /users/api returns all existing created apps, including private ones to Shopify - 34 upvotes, $1900
  158. Stored XSS in Dovetale by application of creator to Shopify - 34 upvotes, $1600
  159. DOM XSS via Shopify.API.Modal.initialize to Shopify - 34 upvotes, $500
  160. Self-XSS in password reset functionality to Shopify - 34 upvotes, $0
  161. [h1-2102] Wholesale - CSRF to Generate Invitation Token for a Customer and Move Customer to Invited Status to Shopify - 34 upvotes, $0
  162. Production Key and Data Found on Subdomain No Longer Operated by Shopify / Dangling DNS to Shopify - 34 upvotes, $0
  163. [Privilege Escalation] Shopify Admin -- Permission from Settings to Customer to Shopify - 33 upvotes, $0
  164. Account takeover intercepting magic link for Arrive app to Shopify - 33 upvotes, $0
  165. Script Editor preview token still working with uninstalled application, even for unpublished script to Shopify - 33 upvotes, $0
  166. Xss At Shopify Email App to Shopify - 33 upvotes, $0
  167. [h1-2102] Improper Access Control at https://shopify.plus/[id]/users/api in operation UpdateOrganizationUserTfaEnforcement to Shopify - 33 upvotes, $0
  168. Ability to see password protected content by bypassing the password page of shopify preview URL for new development stores (as of August 17, 2020) to Shopify - 32 upvotes, $1500
  169. XSS on "widgets.shopifyapps.com" via "stripping" attribute and "shop" parameter to Shopify - 32 upvotes, $1000
  170. IDOR [partners.shopify.com] - User with ONLY Manage apps permission is able to get shops info and staff names from inside the shop to Shopify - 32 upvotes, $500
  171. Cross-site scripting in "Contact customer" form to Shopify - 32 upvotes, $0
  172. Add new managed stores without permission to Shopify - 32 upvotes, $0
  173. XSS in shopshop.myshopify.com/admin/ via twine template injection in "Shopify.API.Modal.input" method when using a malicious app to Shopify - 31 upvotes, $1000
  174. Fetching external resources through svg images to Shopify - 31 upvotes, $0
  175. [h1-2102] Improper Access Control at https://shopify.plus/[id]/users/api in operation UpdateOrganizationUserRole to Shopify - 31 upvotes, $0
  176. H1514 Deanonymizing Exchange Marketplace private listings to Shopify - 30 upvotes, $1000
  177. XSS in shopshop.myshopify.com/admin/ via "Button Objects" in malicious app to Shopify - 30 upvotes, $800
  178. CSRF in all API endpoints when authenticated using HTTP Authentication to Shopify - 30 upvotes, $0
  179. any staff members have the ability to comment in [discounts] he/she can disable comment section it to other staff even the admin of the store to Shopify - 30 upvotes, $0
  180. Stored XSS in https://productreviews.shopifyapps.com/proxy/v4/reviews/product to Shopify - 30 upvotes, $0
  181. Ability to connect an external login service for unverified emails/accounts at accounts.shopify.com to Shopify - 29 upvotes, $1600
  182. IDOR expire other user sessions to Shopify - 29 upvotes, $1000
  183. Shop App - Attacker is able to intercept authorization code during authentication (OAuth) and is able to get access to Microsoft Outlook email account to Shopify - 29 upvotes, $900
  184. Open Redirect at *.myshopify.com/account/login?checkout_url= to Shopify - 29 upvotes, $0
  185. Potentially Sensitive Information on GitHub to Shopify - 29 upvotes, $0
  186. Path Traversal in App Proxy to Shopify - 29 upvotes, $0
  187. Self xss in product reviews to Shopify - 29 upvotes, $0
  188. Senseitive data Related to Shopify Host -> https://shopify.zendesk.com/ to Shopify - 29 upvotes, $0
  189. Attention! Remote Code Execution at http://wpt.ec2.shopify.com/ to Shopify - 28 upvotes, $0
  190. Open redirect in bulk edit to Shopify - 28 upvotes, $0
  191. Bypass report #416983 - Removed Staff members who had "Apps" permission can still modify flow app connections to Shopify - 28 upvotes, $0
  192. subdomain Takeover at blog.exchangemarketplace.com to Shopify - 27 upvotes, $0
  193. Stored - XSS to Shopify - 27 upvotes, $0
  194. GraphQL Introspection Enabled on Shopify API Endpoint (Intended Behavior) to Shopify - 27 upvotes, $0
  195. None permission staff member can identify installed application and products attached to it to Shopify - 26 upvotes, $500
  196. user with no draft order permission can still perform action on draft order's in stocky app (idor) to Shopify - 26 upvotes, $500
  197. Stored XSS on apps.shopify.com to Shopify - 26 upvotes, $500
  198. Stealing users' facebook access tokens - kitcrm.com to Shopify - 26 upvotes, $0
  199. Preview bar: Incomplete message origin validation results in XSS to Shopify - 26 upvotes, $0
  200. [ux.shopify.com] Subdomain takeover to Shopify - 26 upvotes, $0
  201. Ability to generate shipping labels in another store orders to Shopify - 26 upvotes, $0
  202. Sidekiq dashboard exposed at notary.shopifycloud.com to Shopify - 26 upvotes, $0
  203. Staff can use BULK_OPERATIONS_FINISH webhook topic using Graphql without permissions all to Shopify - 26 upvotes, $0
  204. Direct Access To admin Dashboard to Shopify - 26 upvotes, $0
  205. XSS seems to work again after change to linkpop at https://linkpop.com/testnaglinagli to Shopify - 26 upvotes, $0
  206. H1514 Simple phishing using auto-created modal with weak URL-pattern check in incontext_app_link to Shopify - 25 upvotes, $0
  207. Staff with no permissions can listen to Shopify Ping conversations by registering to its different WebSocket Events to Shopify - 25 upvotes, $0
  208. Is the Google Bucket Meant To Be Publicly Listable? https://cdn.shopify.com/shop-assets/ to Shopify - 25 upvotes, $0
  209. Staff can create workflows in Shopify Admin without apps permission to Shopify - 25 upvotes, $0
  210. Low Privileged Staff Member Can Export Billing Charges to Shopify - 24 upvotes, $1900
  211. Bypass GraphQL rate limit by abusing negative cost queries to Shopify - 24 upvotes, $0
  212. H1514 Extract information about other sites (new sites) through Affiliate/Referral pages to Shopify - 24 upvotes, $0
  213. xss triggered in "myshopify.com/admin/product" to Shopify - 24 upvotes, $0
  214. STAFF member with NO Explicit permissions can view ActivityFeed via GraphQL to Shopify - 23 upvotes, $500
  215. Subdomain Takeover in http://genghis-cdn.shopify.io/ pointing to Fastly to Shopify - 23 upvotes, $0
  216. Admin bar: Incomplete message origin validation results in XSS to Shopify - 23 upvotes, $0
  217. H1514 CSRF in Domain transfer allows adding your domain to other user's account to Shopify - 23 upvotes, $0
  218. Apache Flink Dashboard exposure at https://streaming-sales-model-production.flink.shopifykloud.com to Shopify - 23 upvotes, $0
  219. [h1-2102] [Plus] User with Store Management Permission can Make changeDomainEnforcementState - that should be limited to User Management Only to Shopify - 23 upvotes, $0
  220. [h1-2102] HTML injection in packing slips can lead to physical theft to Shopify - 22 upvotes, $900
  221. Order Creation Webhooks can be edited/deleted by STAFF with Settings only permission to Shopify - 22 upvotes, $500
  222. Ability to potentially hit internal NGINX locations on *.myshopify.com by making use of the X-Accel-Redirect header via a configured App Proxy to Shopify - 22 upvotes, $0
  223. Ability to publish a paid theme without purchasing it. to Shopify - 21 upvotes, $2000
  224. XSS on manually entering Postal codes to Shopify - 21 upvotes, $500
  225. H1514 Stored XSS on Wholesale sales channel allows cross-organization data leakage to Shopify - 21 upvotes, $0
  226. H1514 Stored XSS in Return Magic App portal content to Shopify - 21 upvotes, $0
  227. XSS / SELF XSS to Shopify - 21 upvotes, $0
  228. staffOrderNotificationSubscriptionCreate Is Not Blocked Entirely From Staff Member With Settings Permission to Shopify - 21 upvotes, $0
  229. staffOrderNotificationSubscriptionDelete Could Be Used By Staff Member With Settings Permission to Shopify - 21 upvotes, $0
  230. Disconnecting an external login provider does not revoke session to Shopify - 20 upvotes, $1600
  231. Unauthorized access to Zookeeper on http://locutus-zk3.ec2.shopify.com:2181 to Shopify - 20 upvotes, $1000
  232. HTTP-Response-Splitting on v.shopify.com to Shopify - 20 upvotes, $500
  233. Unpublished Product Images can be disclosed to Shopify - 20 upvotes, $500
  234. Inject page in admin panel via Shopify.API.pushState [New Payload] to Shopify - 20 upvotes, $500
  235. Information disclosure ( Google Sales Channel ) to Shopify - 20 upvotes, $500
  236. Bypassing HTML filter in "Packing Slip Template" Lead to SSRF to Internal Kubernetes Endpoints to Shopify - 20 upvotes, $0
  237. https://windsor.shopify.com/ takeover to Shopify - 19 upvotes, $0
  238. Open redirect allows changing iframe content in *.myshopify.com/admin/themes/<id>/editor to Shopify - 19 upvotes, $0
  239. Access to Private Photos of Apps in App section(IDOR) to Shopify - 19 upvotes, $0
  240. Read access to hidden orders,products,customers etc. by limited access Staff member through reference page in Comments (Information disclosure ) to Shopify - 19 upvotes, $0
  241. Password reset link not expired at Stocky App to Shopify - 19 upvotes, $0
  242. Staff Member can Get POS Access Without User Interaction to Shopify - 19 upvotes, $0
  243. Domain Takeover at 3hopify.media to Shopify - 19 upvotes, $0
  244. Store Deletion or Sell without authentication to Shopify - 19 upvotes, $0
  245. Attacker is able to query Github repositories of arbitrary Shopify Hydrogen Users to Shopify - 18 upvotes, $900
  246. Staff with no permissions could possibly list and accept billing promotions to Shopify - 18 upvotes, $600
  247. Improper access check by Kit leads to controlling attributes of store & getting analytics by deleted Store member via dual messenger A/C to Shopify - 18 upvotes, $500
  248. Ability to add address without being an admin or staff in the store via wholesale store to Shopify - 18 upvotes, $500
  249. Twitter Disconnect CSRF to Shopify - 18 upvotes, $0
  250. Publicly Accessible Datadog link to Shopify - 18 upvotes, $0
  251. [h1-2102] Information disclosure - ShopifyPlus add user displays existing Shopify ID fullname to Shopify - 18 upvotes, $0
  252. Missing HMAC validation on /uninstall webhook in Shopify/sample-django-app reference template to Shopify - 18 upvotes, $0
  253. PII disclosure -- Past team members & their email ID(personal email) can be viewed by Staff member with no permissions on Partner Dashboard to Shopify - 17 upvotes, $500
  254. Theme editor oseid parameter is leaked to third-party services through the Referer header which leads to somekind of storefront password bypass. to Shopify - 17 upvotes, $500
  255. Open CouchDB on experiments.ec2.shopify.com:5984 to Shopify - 17 upvotes, $0
  256. Open redirect using checkout_url to Shopify - 17 upvotes, $0
  257. HTML injection in https://interviewing.shopify.com/index.php?candidate= to Shopify - 17 upvotes, $0
  258. Clickjacking in [exchangemarketplace.com] to Shopify - 17 upvotes, $0
  259. Open Redirect - www.shopify.com to Shopify - 17 upvotes, $0
  260. Open Redirect on Login Page of Stocky App to Shopify - 17 upvotes, $0
  261. [https://shipit-sox-staging.shopifycloud.com] Presence of multiple vulnerabilities present in Ruby On Rails to Shopify - 17 upvotes, $0
  262. Read/Write arbitrary (non-HttpOnly) cookies on checkout pages via GoogleAnalyticsAdditionalScripts postMessage handler to Shopify - 16 upvotes, $1600
  263. stored xss in invited team member via email parameter to Shopify - 16 upvotes, $500
  264. Order notifications being sent for a deactivated staff account to Shopify - 16 upvotes, $500
  265. race condition in adding team members to Shopify - 16 upvotes, $0
  266. Cross Site Scripting at https://app.oberlo.com/ to Shopify - 16 upvotes, $0
  267. DOM XSS via Shopify.API.remoteRedirect to Shopify - 16 upvotes, $0
  268. Self XSS in Timeline to Shopify - 16 upvotes, $0
  269. [h1-2102] Partner's team member with no permission can retrieve services financial data to Shopify - 16 upvotes, $0
  270. Improper Input Validation on https://oberlo-image-proxy.shopifycloud.com/ to Shopify - 16 upvotes, $0
  271. After changing the storefront password, the preview link is still valid to Shopify - 16 upvotes, $0
  272. Github base action takeover which is used in github.com/Shopify/unity-buy-sdk to Shopify - 16 upvotes, $0
  273. Self XSS in https://linkpop.com/dashboard/admin to Shopify - 16 upvotes, $0
  274. Add signature to transactions without any permission to Shopify - 15 upvotes, $500
  275. Disclose STUFF member name and make actions. to Shopify - 15 upvotes, $500
  276. XSS on postal codes to Shopify - 15 upvotes, $0
  277. User with no Develop apps permission can Uninstall Custom App to Shopify - 15 upvotes, $0
  278. [h1-2102] [PLUS] User with Store Management Permission can Make enforceSamlOrganizationDomains call - that should be limited to User Management Only to Shopify - 15 upvotes, $0
  279. H1514 Get access to non public information by pivoting with graphql queries to Shopify - 14 upvotes, $1500
  280. Open redirection in OAuth to Shopify - 14 upvotes, $500
  281. Reflective XSS on wholesale.shopify.com to Shopify - 14 upvotes, $500
  282. Access to Splunk at https://apt.ec2.shopify.com:8089 to Shopify - 14 upvotes, $500
  283. Staff member with no permission can delete POS staff from account settings to Shopify - 14 upvotes, $500
  284. your-store.myshopify.com preview link is leak on third party website lead to preview all action from store owner Without store Password. to Shopify - 14 upvotes, $500
  285. SVG parser loads external resources on image upload to Shopify - 14 upvotes, $0
  286. Unauthenticated Stored XSS on <any>.myshopify.com via checkout page to Shopify - 14 upvotes, $0
  287. Stored XSS in partners dashboard to Shopify - 14 upvotes, $0
  288. Screenshot Service leaks X-ABS-App-Token to Shopify - 14 upvotes, $0
  289. Subdomain Takeover at course.oberlo.com to Shopify - 14 upvotes, $0
  290. IDOR on stocky application-Low Stock-Varient-Settings-Columns to Shopify - 13 upvotes, $750
  291. [apps.shopify.com] Open Redirect to Shopify - 13 upvotes, $500
  292. Stored XSS at 'Buy Button' page to Shopify - 13 upvotes, $500
  293. Subdomain takeover on s3.shopify.com to Shopify - 13 upvotes, $500
  294. From full-access account to Account Owner to Shopify - 13 upvotes, $500
  295. Stored XSS in *.myshopify.com to Shopify - 13 upvotes, $0
  296. SQL Exception thrown during product import to Shopify - 13 upvotes, $0
  297. Add store to new partner account without confirming email address. to Shopify - 13 upvotes, $0
  298. Improper deep link validation to Shopify - 13 upvotes, $0
  299. shopifyapps.com XSS on sales channels via currency formatting to Shopify - 12 upvotes, $1000
  300. S3 Buckets open to the world thanks to 'Authenticated Users' ACL to Shopify - 12 upvotes, $1000
  301. Orders full read for a staff with only Customers permissions. to Shopify - 12 upvotes, $800
  302. H1514 Lack of access control on edit packing slip template to Shopify - 12 upvotes, $500
  303. Shopify's SF and LA offices Dashboard Information disclosed via Public Gist to Shopify - 12 upvotes, $500
  304. amazon aws s3 bucket content is public :- http://shopify.com.s3.amazonaws.com/ to Shopify - 12 upvotes, $0
  305. (BYPASS) Open Redirect after login at http://ecommerce.shopify.com to Shopify - 12 upvotes, $0
  306. Access to Splunk via shard3-db2.ec2.shopify.com endpoint to Shopify - 12 upvotes, $0
  307. Unsanitized Location Name in POS Channel can lead to XSS in Orders Timeline to Shopify - 12 upvotes, $0
  308. XSS in SHOPIFY: Unsanitized Supplier Name can lead to XSS in Transfers Timeline to Shopify - 12 upvotes, $0
  309. Authentication Bypass on monitoring server to Shopify - 12 upvotes, $0
  310. Open redirection in OAuth to Shopify - 12 upvotes, $0
  311. Open Redirect in www.shopify.dev Environment to Shopify - 12 upvotes, $0
  312. [h1-2102] [Yaworski's Broskis] Suspected overcharge and chargebacks in PoS to Shopify - 12 upvotes, $0
  313. password less login token expiration issue to Shopify - 11 upvotes, $500
  314. [CSRF] Install premium themes to Shopify - 11 upvotes, $0
  315. H1514 Shopify API ruby SDK session setup lacks input validation, resulting in SSRF and leakage of client secret to Shopify - 11 upvotes, $0
  316. Password protection can be removed for newly created development store to Shopify - 11 upvotes, $0
  317. The POS app doesn't revoke the Xauth token to Shopify - 11 upvotes, $0
  318. Password reset token leak via "Host header" on third party website to Shopify - 11 upvotes, $0
  319. [h1-2102] [Plus] User with Store Management Permission can Make convertUsersFromSaml/convertUsersToSaml - that should be limited to User Management to Shopify - 11 upvotes, $0
  320. An administrator without any permission is able to get order notifications using his APNS Token. to Shopify - 10 upvotes, $500
  321. Reflected XSS in cart at hardware.shopify.com to Shopify - 10 upvotes, $500
  322. H1514 Wholesale customer without checkout permission can complete purchases to Shopify - 10 upvotes, $0
  323. Privilege Escalation in Point Of Sale Application from POS Manage Staff Role to potentially Store Owner to Shopify - 10 upvotes, $0
  324. XSS stored in the Shopify Email app to Shopify - 10 upvotes, $0
  325. Authentication Failed Mobile version to Shopify - 9 upvotes, $500
  326. Missing of csrf protection to Shopify - 9 upvotes, $500
  327. Content Spoofing to Shopify - 9 upvotes, $0
  328. SSL cookie without secure flag set to Shopify - 9 upvotes, $0
  329. SSRF via 'Add Image from URL' feature to Shopify - 9 upvotes, $0
  330. Delete/modify your own comment after limited access(IDOR) to Shopify - 9 upvotes, $0
  331. [ecommerce.shopify.com] Invalidated redirection to Shopify - 9 upvotes, $0
  332. ShopifyAPI is vulnerable to timing attacks. to Shopify - 9 upvotes, $0
  333. API Webhooks Fire And Are Unlisted After Permissions Removed to Shopify - 9 upvotes, $0
  334. Potential SSRF and disclosure of sensitive site on *shopifycloud.com to Shopify - 9 upvotes, $0
  335. Subdomain Takeover of multiple *.ttcdn.co domains to Shopify - 9 upvotes, $0
  336. A staff without export customers permissions can still export customers CSV file to Shopify - 9 upvotes, $0
  337. [h1-2102] Stored XSS in product description via productUpdate GraphQL query leads to XSS at handshake-web-internal.shopifycloud.com/products/[ID] to Shopify - 8 upvotes, $1600
  338. Privilege Escalation - A MEMBER with no ACCESS to ORDERS can still access the orders by using Order Printer APP to Shopify - 8 upvotes, $1000
  339. H1514 Ability to Edit Packaging Slip Templates and View Product & Shipping Information by a low privileged staff in a Sandbox Store to Shopify - 8 upvotes, $500
  340. [h1-2102] Break permissions waterfall to Shopify - 8 upvotes, $500
  341. Same the Url to Shopify - 8 upvotes, $500
  342. Missing spf flags for myshopify.com to Shopify - 8 upvotes, $0
  343. Shopify android client all API request's response leakage, including access_token, cookie, response header, response body content to Shopify - 8 upvotes, $0
  344. (FULL PATH DISCLOSURE) Unknown MySQL server host 'shardm-reader.chi2.shopify.io' to Shopify - 8 upvotes, $0
  345. Open Redirect in shopify app URL to Shopify - 8 upvotes, $0
  346. [out-of-scope] toxiproxy: Lack of CSRF protection allows an attacker to gain access to internal Shopify network to Shopify - 8 upvotes, $0
  347. Stocky App Administrator can create a backdoor admin account by using an existing POS User to Shopify - 8 upvotes, $0
  348. damage to the timeline so that comment fields cannot be displayed or not available to all members in the store to Shopify - 8 upvotes, $0
  349. Partner's non-verified business email change reflected into Shopify Collaborator Request to Shopify - 8 upvotes, $0
  350. Customer's full name disclosure via Shopify Chat (by email lookup) to Shopify - 8 upvotes, $0
  351. Order lookup features of Shopify Chat Application leads to customer orders enumeration due to lack of user input validation to Shopify - 8 upvotes, $0
  352. The authentication code when activating 2FA can be used again to log in to Shopify - 8 upvotes, $0
  353. store internal email disclosed through shopify-data-exporter to Shopify - 8 upvotes, $0
  354. Staff members with no permission can access to the files, uploaded by the administrator to Shopify - 7 upvotes, $500
  355. Bypass For #997350 your-store.myshopify.com preview link is leak on third party website Via Online Store to Shopify - 7 upvotes, $500
  356. XSS in experts.shopify.com to Shopify - 7 upvotes, $0
  357. Force 500 Internal Server Error on any shop (for one user) to Shopify - 7 upvotes, $0
  358. XSS in Draft Orders in Timeline i SHOPIFY Admin Site! to Shopify - 7 upvotes, $0
  359. Staff member can delete Private Apps to Shopify - 7 upvotes, $0
  360. View all deleted comments and rating of any app . to Shopify - 7 upvotes, $0
  361. Payment gateway status transferred to Shopify without authentication to Shopify - 7 upvotes, $0
  362. Deleted Post and Administrative Function Access in eCommerce Forum to Shopify - 7 upvotes, $0
  363. Stored passive XSS at scheduled posts (kitcrm.com) to Shopify - 7 upvotes, $0
  364. Redirect in adding advance cash on delivery app to Shopify - 7 upvotes, $0
  365. access permission is not revoked even if the email has been deleted or changed on the partner account -partners.shopify- to Shopify - 7 upvotes, $0
  366. Admin web sessions remain active after logout of Shopify ID to Shopify - 7 upvotes, $0
  367. Unauthorized access to all collections, products, pages from other stores to Shopify - 6 upvotes, $2500
  368. 'Limited' RCE in certain places where Liquid is accepted to Shopify - 6 upvotes, $1500
  369. STAFF "No-Permissions" on the Store can retrieve the details Order via exchangeReceiptSend to Shopify - 6 upvotes, $1000
  370. Stored XSS in the Shopify Discussion Forums to Shopify - 6 upvotes, $500
  371. Open Redirect after login at http://ecommerce.shopify.com to Shopify - 6 upvotes, $500
  372. File name and folder enumeration. to Shopify - 6 upvotes, $500
  373. Bypassed password authentication before enabling OTP verification to Shopify - 6 upvotes, $500
  374. TCP Source Port Pass Firewall to Shopify - 6 upvotes, $0
  375. Privilege escalation and circumvention of permission to limited access user to Shopify - 6 upvotes, $0
  376. [livechat.shopify.com] Cookie bomb at customer chats to Shopify - 6 upvotes, $0
  377. Attach Pinterest account - no State/CSRF parameter in Oauth Call back to Shopify - 6 upvotes, $0
  378. Open Redirect possible in https://www.shopify.com/admin/ to Shopify - 6 upvotes, $0
  379. Arbitrary write on s3://shopify-delivery-app-storage/files to Shopify - 5 upvotes, $2000
  380. Shop admin can change external login services to Shopify - 5 upvotes, $1000
  381. create staff member without owner access to Shopify - 5 upvotes, $1000
  382. [www.*.myshopify.com] CRLF Injection to Shopify - 5 upvotes, $500
  383. get users information without full access to Shopify - 5 upvotes, $500
  384. An administrator without the 'Settings' permission is able to see payment gateways to Shopify - 5 upvotes, $500
  385. XSS in my.shopify.com in widget to Shopify - 5 upvotes, $500
  386. comment out causes information disclosure to Shopify - 5 upvotes, $0
  387. Xss in website's link to Shopify - 5 upvotes, $0
  388. SSRF via 'Insert Image' feature of Products/Collections/Frontpage to Shopify - 5 upvotes, $0
  389. Paid account can review\download any invoice of any other shop to Shopify - 5 upvotes, $0
  390. Staff members with no permission to access domains can access them. to Shopify - 5 upvotes, $0
  391. XSS on hardware.shopify.com to Shopify - 5 upvotes, $0
  392. Full access at an internal service of Shopify to Shopify - 5 upvotes, $0
  393. increased privileges on staff account to Shopify - 5 upvotes, $0
  394. Subdomain takeover in help.tictail.com pointing to Zendesk (a Shopify acquisition) to Shopify - 5 upvotes, $0
  395. *.shopify.com - Authentication bypass to Shopify - 5 upvotes, $0
  396. xss on polaris.shopify.com/demo using postMessage to Shopify - 5 upvotes, $0
  397. unauthorized access to all customers first and last name to Shopify - 4 upvotes, $2500
  398. Bypass access restrictions from API to Shopify - 4 upvotes, $1000
  399. change Login Services settings without owner access to Shopify - 4 upvotes, $1000
  400. CSRF token fixation in facebook store app that can lead to adding attacker to victim acc to Shopify - 4 upvotes, $500
  401. customers password hash leak!!!! to Shopify - 4 upvotes, $500
  402. Some S3 Buckets are world readable (and one is world writeable) to Shopify - 4 upvotes, $500
  403. Missing authorization check on dashboard overviews to Shopify - 4 upvotes, $500
  404. "Remember me" token generated when "Remember me" box unchecked to Shopify - 4 upvotes, $500
  405. Strored Cross Site Scripting to Shopify - 4 upvotes, $500
  406. XSS - URL Redirects to Shopify - 4 upvotes, $0
  407. XSS in myshopify.com Admin site in TAX Overrides to Shopify - 4 upvotes, $0
  408. Header Misconfiguration - PHP API to Shopify - 4 upvotes, $0
  409. [persistent cross-site scripting] customers can target admins to Shopify - 4 upvotes, $0
  410. Reflected XSS in chat. to Shopify - 4 upvotes, $0
  411. Notification request disclose private information about other myshopify accounts to Shopify - 4 upvotes, $0
  412. Prevent Shop Admin From Seeing his Installed Apps / Install Persistent Unremovable App to Shopify - 4 upvotes, $0
  413. Domain takoever - https://sellocdn.com to Shopify - 4 upvotes, $0
  414. Unauthorized access to any Store Admin's First & Last name to Shopify - 4 upvotes, $0
  415. deleted staff member can add his amazon marketplace web services account to the store. to Shopify - 4 upvotes, $0
  416. CSV Excel Macro Injection Vulnerability in export list of current users - app.shopify.com to Shopify - 4 upvotes, $0
  417. [CSRF] Activate PayPal Express Checkout to Shopify - 4 upvotes, $0
  418. Non-owner user can remove online store channel and re-add it. to Shopify - 4 upvotes, $0
  419. Full access to Amazon S3 bucket containing AWS CloudTrail logs to Shopify - 4 upvotes, $0
  420. Some store settings/data are accessible to "No Access" permission users on GraphQL LiveView operation to Shopify - 4 upvotes, $0
  421. Arbitrary read on s3://shopify-delivery-app-storage/files to Shopify - 3 upvotes, $1500
  422. Unauthenticated access to details of hidden products in any shop via title emuneration to Shopify - 3 upvotes, $1000
  423. XSS at importing Product List to Shopify - 3 upvotes, $500
  424. XSS at Bulk editing products to Shopify - 3 upvotes, $500
  425. Accessing Payments page and adding payment methods with limited access accounts to Shopify - 3 upvotes, $500
  426. List of devices is accessible regardless of the account limitations to Shopify - 3 upvotes, $500
  427. A 'Full access' administrator is able to see the shop owners user details to Shopify - 3 upvotes, $500
  428. Apps can access 'channels' beta api to Shopify - 3 upvotes, $500
  429. CSRF on https://shopify.com/plus to Shopify - 3 upvotes, $500
  430. Lack of SSL Pinning on POS Application ( iOS ) to Shopify - 3 upvotes, $0
  431. Multiple issues on Checkout Process to Shopify - 3 upvotes, $0
  432. XSS on support.shopify.com to Shopify - 3 upvotes, $0
  433. Expire User Sessions in Admin Site does not expire user session in Shopify Application in IOS to Shopify - 3 upvotes, $0
  434. XSS https://delivery.shopifyapps.com/ (Digital Downloads App in myshopify.com) to Shopify - 3 upvotes, $0
  435. Invitation issue to Shopify - 3 upvotes, $0
  436. Passwords Returned in Later Responses. to Shopify - 3 upvotes, $0
  437. The POS Firmware is leaking the root Password which can be used for unauthorized access to the device. to Shopify - 3 upvotes, $0
  438. Privilege escalation vulnerability to Shopify - 3 upvotes, $0
  439. Bypassing password requirement during deletion of accout to Shopify - 3 upvotes, $0
  440. First & Last Name Disclosure of any Shopify Store Admin to Shopify - 3 upvotes, $0
  441. XSS in creating tweets to Shopify - 3 upvotes, $0
  442. Get analytics token using only apps permission to Shopify - 3 upvotes, $0
  443. unauthorized access to all collections name to Shopify - 2 upvotes, $2000
  444. OrderListInitial leaks order details to Shopify - 2 upvotes, $1500
  445. XSS at Bulk editing ProductVariants to Shopify - 2 upvotes, $500
  446. XSS https://www.shopify.com/signup to Shopify - 2 upvotes, $500
  447. www.shopify.com XSS on blog pages via sharing buttons to Shopify - 2 upvotes, $500
  448. Stored XSS in https://checkout.shopify.com/ to Shopify - 2 upvotes, $500
  449. XSS on https://app.shopify.com/ to Shopify - 2 upvotes, $500
  450. XSS in Myshopify Admin Site in DISCOUNTS to Shopify - 2 upvotes, $0
  451. Bulk Discount App in myshopify.com exposes http://bulkdiscounts.shopifyapps.com vulnerable to XSS to Shopify - 2 upvotes, $0
  452. Reflected XSS in chat to Shopify - 2 upvotes, $0
  453. XSS on ecommerce.shopify.com to Shopify - 2 upvotes, $0
  454. Body injection in mailto link while commenting shop blog to Shopify - 2 upvotes, $0
  455. Cookie securing your "Opening soon" store is not secured against XSS to Shopify - 2 upvotes, $0
  456. CSRF in Connecting Pinterest Account to Shopify - 2 upvotes, $0
  457. Stored XSS in /admin/orders to Shopify - 2 upvotes, $0
  458. Injection via CSV Export feature in Admin Orders to Shopify - 2 upvotes, $0
  459. staff memeber can install apps even if have limitied access to Shopify - 2 upvotes, $0
  460. Redirect url after login is not validated to Shopify - 2 upvotes, $0
  461. Setting Arbitrary Cookie at kitcrm.com to Shopify - 2 upvotes, $0
  462. www.shopify.com XSS via third-party script to Shopify - 1 upvotes, $500
  463. many xss in widgets.shopifyapps.com to Shopify - 1 upvotes, $500
  464. XSS on hardware.shopify.com to Shopify - 1 upvotes, $500
  465. xss in the all widgets of shopifyapps.com to Shopify - 1 upvotes, $500
  466. Stored XSS via "Free Shipping" option (Discounts) to Shopify - 1 upvotes, $500