CVE-2025-51586
- EPSS 0.04%
- Published 08.09.2025 00:00:00
- Last modified 12.09.2025 20:49:23
An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.
CVE-2025-25692
- EPSS 0.09%
- Published 30.07.2025 00:00:00
- Last modified 06.08.2025 16:21:43
A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.
CVE-2025-25691
- EPSS 0.1%
- Published 30.07.2025 00:00:00
- Last modified 06.08.2025 16:25:47
A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.
CVE-2025-1230
- EPSS 0.05%
- Published 12.02.2025 11:15:11
- Last modified 12.02.2025 11:15:11
Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a spe...
CVE-2024-36626
- EPSS 0.22%
- Published 29.11.2024 17:15:07
- Last modified 15.09.2025 18:16:14
In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.
CVE-2024-41651
- EPSS 35.7%
- Published 12.08.2024 17:15:17
- Last modified 09.10.2024 18:15:05
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack ne...
CVE-2024-34991
- EPSS 0.2%
- Published 24.06.2024 22:15:10
- Last modified 21.11.2024 09:19:40
In the module "Axepta" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credit card information (expiry date) / postal address / email / etc. without restriction due to a lack of permissions control.
CVE-2024-34989
- EPSS 0.09%
- Published 21.06.2024 22:15:10
- Last modified 21.11.2024 09:19:39
In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injection via `PrestaPDFProductListModuleFrontController::queryDb().'
CVE-2024-36677
- EPSS 0.31%
- Published 19.06.2024 21:15:57
- Last modified 21.11.2024 09:22:31
In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct link to connect to each customer account of the Shop if the module is not installed OR if a secret accessible to administrator is ...
CVE-2024-34994
- EPSS 0.16%
- Published 19.06.2024 21:15:57
- Last modified 21.11.2024 09:19:40
In the module "Channable" (channable) up to version 3.2.1 from Channable for PrestaShop, a guest can perform SQL injection via `ChannableFeedModuleFrontController::postProcess()`.