← All vendors

Is Shopify down?

OperationalNo problems detected · checked 7m ago

No — Shopify is operational right now.

All Systems Operational

Shopify's official status page

Shopify uptime, as reported

Last 30 days
97.81%
Last 90 days
99.03%
Incidents (30d)
6
Incidents (90d)
9

Calculated from status changes we recorded on Shopify's own status page. Scheduled maintenance is not counted as downtime.

Recent status changes

  1. OperationalAll Systems Operational5d ago
  2. DegradedPartially Degraded Service5d ago
  3. OperationalAll Systems Operational5d ago
  4. DegradedMinor Service Outage5d ago
  5. OperationalAll Systems Operational8d ago
  6. DegradedPartially Degraded Service8d ago
  7. OperationalAll Systems Operational17d ago
  8. DegradedPartially Degraded Service17d ago

Vulnerabilities affecting Shopify

  • CVE-2026-55685MediumCVSS 7.51mo ago

    React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been fixed in version 7.18.0.

  • CVE-2026-53669LowCVSS 6.11mo ago

    React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0.

  • CVE-2026-53668LowCVSS 6.91mo ago

    React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version 7.13.0.

  • CVE-2026-53667LowCVSS 6.91mo ago

    React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0.

  • CVE-2026-53666LowCVSS 6.11mo ago

    React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which would in turn trigger an outbound network request. This is only possible with very specific (and unlikely) application-layer code. Note that this does not impact an application if it is using Declarative Mode. It only impacts Framework Mode and Data Mode applications that perform manual SSR/hydration. This issue has been fixed in version 7.18.0.

Stop checking status pages one at a time

ThreatLoops watches Shopify and the rest of your stack, and pushes outages and exploited vulnerabilities to Slack, Teams or a webhook — one short list a day instead of twenty browser tabs.

Other Commerce tools

Shopify status questions

Is Shopify down right now?
No — Shopify is operational right now. We last checked 7m ago against Shopify's official status page.
Is it Shopify or is it just me?
If this page says operational and you still can't connect, the problem is usually local — DNS, a proxy, SSO, or a single region. Shopify recorded 6 status events in the last 30 days.
How do I get alerted when Shopify goes down?
Add Shopify to your stack in ThreatLoops and outages are pushed to Slack, Microsoft Teams or a webhook — alongside vulnerabilities affecting the same vendor.