Prestashop

Prestashop

104 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 14.05.2026 20:44:08
  • Zuletzt bearbeitet 15.05.2026 14:30:03

PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Conta...

  • EPSS 0.03%
  • Veröffentlicht 26.03.2026 21:42:33
  • Zuletzt bearbeitet 01.04.2026 13:33:58

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.

  • EPSS 0.01%
  • Veröffentlicht 26.03.2026 21:41:13
  • Zuletzt bearbeitet 01.04.2026 13:40:03

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-offic...

  • EPSS 0.06%
  • Veröffentlicht 06.02.2026 20:47:24
  • Zuletzt bearbeitet 19.02.2026 17:27:30

PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether...

  • EPSS 0.94%
  • Veröffentlicht 08.09.2025 00:00:00
  • Zuletzt bearbeitet 12.09.2025 20:49:23

An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.

Exploit
  • EPSS 0.52%
  • Veröffentlicht 30.07.2025 00:00:00
  • Zuletzt bearbeitet 06.08.2025 16:25:47

A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

Exploit
  • EPSS 0.39%
  • Veröffentlicht 30.07.2025 00:00:00
  • Zuletzt bearbeitet 06.08.2025 16:21:43

A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

  • EPSS 0.07%
  • Veröffentlicht 12.02.2025 11:15:11
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a spe...

  • EPSS 0.05%
  • Veröffentlicht 29.11.2024 17:15:07
  • Zuletzt bearbeitet 15.09.2025 18:16:14

In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.

Exploit
  • EPSS 32.33%
  • Veröffentlicht 12.08.2024 17:15:17
  • Zuletzt bearbeitet 09.10.2024 18:15:05

An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack ne...