CVE-2026-44212
- EPSS 0.06%
- Veröffentlicht 14.05.2026 20:44:08
- Zuletzt bearbeitet 15.05.2026 14:30:03
PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Conta...
CVE-2026-33674
- EPSS 0.03%
- Veröffentlicht 26.03.2026 21:42:33
- Zuletzt bearbeitet 01.04.2026 13:33:58
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.
CVE-2026-33673
- EPSS 0.01%
- Veröffentlicht 26.03.2026 21:41:13
- Zuletzt bearbeitet 01.04.2026 13:40:03
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-offic...
CVE-2026-25597
- EPSS 0.06%
- Veröffentlicht 06.02.2026 20:47:24
- Zuletzt bearbeitet 19.02.2026 17:27:30
PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether...
CVE-2025-51586
- EPSS 0.94%
- Veröffentlicht 08.09.2025 00:00:00
- Zuletzt bearbeitet 12.09.2025 20:49:23
An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.
CVE-2025-25691
- EPSS 0.52%
- Veröffentlicht 30.07.2025 00:00:00
- Zuletzt bearbeitet 06.08.2025 16:25:47
A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.
CVE-2025-25692
- EPSS 0.39%
- Veröffentlicht 30.07.2025 00:00:00
- Zuletzt bearbeitet 06.08.2025 16:21:43
A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.
CVE-2025-1230
- EPSS 0.07%
- Veröffentlicht 12.02.2025 11:15:11
- Zuletzt bearbeitet 15.04.2026 00:35:42
Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a spe...
CVE-2024-36626
- EPSS 0.05%
- Veröffentlicht 29.11.2024 17:15:07
- Zuletzt bearbeitet 15.09.2025 18:16:14
In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.
CVE-2024-41651
- EPSS 32.33%
- Veröffentlicht 12.08.2024 17:15:17
- Zuletzt bearbeitet 09.10.2024 18:15:05
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack ne...