Prestashop

Prestashop

107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 07.09.2026 08:39:46
  • Zuletzt bearbeitet 08.09.2026 19:15:18

Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse proxy, load bala...

  • EPSS 0.22%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 09.09.2026 16:04:24

xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input is stored in the database without HTML sanitization and rendered in Smar...

  • EPSS 0.31%
  • Veröffentlicht 18.05.2026 00:00:00
  • Zuletzt bearbeitet 18.05.2026 20:17:10

An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upsshipping/logs/, and /modules/upsshipping/lib/UPSBaseApi.php components

  • EPSS 0.33%
  • Veröffentlicht 14.05.2026 20:44:08
  • Zuletzt bearbeitet 15.05.2026 14:30:03

PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Conta...

  • EPSS 0.24%
  • Veröffentlicht 26.03.2026 21:42:33
  • Zuletzt bearbeitet 01.04.2026 13:33:58

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.

  • EPSS 0.27%
  • Veröffentlicht 26.03.2026 21:41:13
  • Zuletzt bearbeitet 01.04.2026 13:40:03

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-offic...

  • EPSS 0.27%
  • Veröffentlicht 06.02.2026 20:47:24
  • Zuletzt bearbeitet 19.02.2026 17:27:30

PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether...

  • EPSS 0.82%
  • Veröffentlicht 08.09.2025 00:00:00
  • Zuletzt bearbeitet 12.09.2025 20:49:23

An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.

Exploit
  • EPSS 0.77%
  • Veröffentlicht 30.07.2025 00:00:00
  • Zuletzt bearbeitet 05.07.2026 16:19:18

A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

Exploit
  • EPSS 0.63%
  • Veröffentlicht 30.07.2025 00:00:00
  • Zuletzt bearbeitet 05.07.2026 01:21:26

A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.