CVE-2024-33272
- EPSS 0.39%
- Veröffentlicht 29.04.2024 20:15:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
SQL injection vulnerability in KnowBand for PrestaShop autosuggest before 2.0.0 allows an attacker to run arbitrary SQL commands via the AutosuggestSearchModuleFrontController::initContent(), and AutosuggestSearchModuleFrontController::getKbProducts(...
CVE-2024-33276
- EPSS 0.6%
- Veröffentlicht 29.04.2024 20:15:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbitrary SQL commands via the PreorderModel::getIdProductAttributesByIdAttributes() method.
CVE-2024-25845
- EPSS 0.59%
- Veröffentlicht 08.03.2024 02:15:50
- Zuletzt bearbeitet 05.05.2025 15:02:24
In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions.
CVE-2024-26469
- EPSS 0.31%
- Veröffentlicht 03.03.2024 10:15:06
- Zuletzt bearbeitet 13.05.2025 14:22:16
Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to cause a denial of service (DoS) and escalate privileges via the url paramete...
CVE-2024-26129
- EPSS 0.61%
- Veröffentlicht 19.02.2024 22:15:49
- Zuletzt bearbeitet 17.01.2025 15:44:18
PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. A patch is available in version 8.1.4.
CVE-2024-21628
- EPSS 0.39%
- Veröffentlicht 02.01.2024 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:54:45
PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possible to store a cross-site scripting payload in the database. The impact is low because the HTML is not...
CVE-2024-21627
- EPSS 0.52%
- Veröffentlicht 02.01.2024 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:54:45
PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` method. Some modules using the `isCleanHTML` method could be vulnerable to cross-site scripting. Versi...
CVE-2023-43663
- EPSS 0.35%
- Veröffentlicht 28.09.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:24:34
PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit ...
CVE-2023-43664
- EPSS 0.39%
- Veröffentlicht 28.09.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:24:34
PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list all modules without any access rights: method `ajaxProcessGetPossibleHookingListForModule` doesn't check access rights. This issue ...
CVE-2023-39525
- EPSS 0.86%
- Veröffentlicht 07.08.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:15:36
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path that uses the traversal path. Ve...