Vulnerabilities
112 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-33673 +1 in the same advisory: …33674 | PrestaShop is an open source e-commerce web application. PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available. NVD description · AI analysis pending | 5.4 group max | <1% |
| — | ||
| CVE-2026-25597 | PrestaShop is an open source e-commerce web application. PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. This vulnerability is fixed in 8.2.4 and 9.0.3. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2025-61922 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist. NVD description · AI analysis pending | 9.1 group max | <1% |
| — | ||
| CVE-2025-51586 | An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the re An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature. NVD description · AI analysis pending | 3.7 | <1% |
| — | ||
| CVE-2025-25691 +1 in the same advisory: …25692 | A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request. A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2024-36626 | In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php. In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2024-41651 | An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack network requests made by an admin user (who, by design, is allowed to change the code that is running on the server). NVD description · AI analysis pending | 8.1 | 1% | PoC |
| — | |
| CVE-2024-36684 | In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-34716 +1 in the same advisory: …34717 | PrestaShop is an open source e-commerce web application. PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. The script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. This vulnerability is patched in 8.1.6. A workaround is to disable the customer-thread feature-flag. NVD description · AI analysis pending | 6.1 group max | 56% |
| — | ||
| CVE-2024-28392 | SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsu SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-25843 | In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQ In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-26129 | PrestaShop is an open-source e-commerce platform. PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. A patch is available in version 8.1.4. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2023-50028 | In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL injection. In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL injection. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-48926 | An issue in 202 ecommerce Advanced Loyalty Program: An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2024-21627 +1 in the same advisory: …21628 | PrestaShop is an open-source e-commerce platform. PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` method. Some modules using the `isCleanHTML` method could be vulnerable to cross-site scripting. Versions 8.1.3 and 1.7.8.11 contain a patch for this issue. The best workaround is to use the `HTMLPurifier` library to sanitize html input coming from users. The library is already available as a dependency in the PrestaShop project. Beware though that in legacy object models, fields of `HTML` type will call `isCleanHTML`. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2023-47110 | blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance allows modifying any value in the configuration table. This vulnerability has been patched in version 5.1.4. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2023-47109 | PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When adding a block in blockreassurance module, a BO user can modify the http request and give the path of any file in the project instead of an image. When deleting the block from the BO, the file will be deleted. It is possible to make the website completely unavailable by removing index.php for example. This issue has been patched in version 5.1.4. NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2023-43664 +1 in the same advisory: …43663 | PrestaShop is an Open Source e-commerce web application. PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list all modules without any access rights: method `ajaxProcessGetPossibleHookingListForModule` doesn't check access rights. This issue has been addressed in commit `15bd281c` which is included in version 8.1.2. Users are advised to upgrade. There are no known workaround for this issue. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2022-45447 +1 in the same advisory: …45448 | M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerability. M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerability. The “f” parameter is not properly checked in the resource /m4pdf/pdf.php, returning any file given its relative path. An attacker that exploits this vulnerability could download /etc/passwd from the server if the file exists. NVD description · AI analysis pending | 6.5 group max | <1% |
| — | ||
| CVE-2023-39526 | PrestaShop is an open source e-commerce web application. PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2023-33777 | An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversal attack. An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversal attack. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2023-30153 | An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote attackers An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote attackers to execute arbitrary SQL commands via the ajax.php front controller. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2023-33279 | In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-30192 | Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find(). Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find(). NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2023-30194 | Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). NVD description · AI analysis pending | 9.8 | 32% | PoC |
| — | |
| CVE-2023-30282 | PrestaShop scexportcustomers <= 3.6.1 is vulnerable to Incorrect Access Control. PrestaShop scexportcustomers <= 3.6.1 is vulnerable to Incorrect Access Control. Due to a lack of permissions' control, a guest can access exports from the module which can lead to leak of personal information from customer table. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-30838 | PrestaShop is an Open Source e-commerce web application. PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop misses hijackable events which can lead to cross-site scripting (XSS) injection, allowed by the presence of pre-setup `@keyframes` methods. This XSS, which hijacks HTML attributes, can be triggered without any interaction by the visitor/administrator, which makes it as dangerous as a trivial XSS attack. Contrary to other attacks which target HTML attributes and are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. Versions 8.0.4 and 1.7.8.9 contain a fix for this issue. NVD description · AI analysis pending | 9.9 group max | 1% |
| — | ||
| CVE-2023-27569 +1 in the same advisory: …27570 | The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header. The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-25206 | PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection. PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2023-25207 | PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php. PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-25170 | PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enable same-site attackers to bypass the CSRF protection mechanism by performing an attack similar to a session-fixation. The problem is fixed in version 8.0.1. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2023-24763 | In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0. In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2022-46158 | PrestaShop is an open-source e-commerce solution. PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem access for users. Users may have been able to view the contents of the upload directory without appropriate permissions. This issue has been addressed and users are advised to upgrade to version 1.7.8.8. There are no known workarounds for this issue. NVD description · AI analysis pending | 4.3 | <1% |
| — |