Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
5.3
CVE-2026-92810
- EPSS 0.2%
- Veröffentlicht 16.09.2026 20:32:56
- Zuletzt bearbeitet 22.09.2026 20:43:58
PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist ide...
8.8
CVE-2022-31101
- EPSS 22.72%
- Veröffentlicht 27.06.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 07:03:53
prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. T...
1