Prestashop

Prestashop

107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 29.04.2024 20:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SQL injection vulnerability in KnowBand for PrestaShop autosuggest before 2.0.0 allows an attacker to run arbitrary SQL commands via the AutosuggestSearchModuleFrontController::initContent(), and AutosuggestSearchModuleFrontController::getKbProducts(...

  • EPSS 0.6%
  • Veröffentlicht 29.04.2024 20:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbitrary SQL commands via the PreorderModel::getIdProductAttributesByIdAttributes() method.

  • EPSS 0.59%
  • Veröffentlicht 08.03.2024 02:15:50
  • Zuletzt bearbeitet 05.05.2025 15:02:24

In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions.

  • EPSS 0.31%
  • Veröffentlicht 03.03.2024 10:15:06
  • Zuletzt bearbeitet 13.05.2025 14:22:16

Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to cause a denial of service (DoS) and escalate privileges via the url paramete...

  • EPSS 0.61%
  • Veröffentlicht 19.02.2024 22:15:49
  • Zuletzt bearbeitet 17.01.2025 15:44:18

PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. A patch is available in version 8.1.4.

  • EPSS 0.39%
  • Veröffentlicht 02.01.2024 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:54:45

PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possible to store a cross-site scripting payload in the database. The impact is low because the HTML is not...

  • EPSS 0.52%
  • Veröffentlicht 02.01.2024 21:15:10
  • Zuletzt bearbeitet 21.11.2024 08:54:45

PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` method. Some modules using the `isCleanHTML` method could be vulnerable to cross-site scripting. Versi...

  • EPSS 0.35%
  • Veröffentlicht 28.09.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 08:24:34

PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit ...

  • EPSS 0.39%
  • Veröffentlicht 28.09.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 08:24:34

PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list all modules without any access rights: method `ajaxProcessGetPossibleHookingListForModule` doesn't check access rights. This issue ...

  • EPSS 0.86%
  • Veröffentlicht 07.08.2023 21:15:10
  • Zuletzt bearbeitet 21.11.2024 08:15:36

PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path that uses the traversal path. Ve...