Skip to main content

Vendor archive

prestashop CVEs

Beta · best-effort

128 CVEs tagged to vendor prestashop29 Critical, 24 High, 71 Medium, 4 Low, 0 Unrated.

CVE-2026-33674

Published Mar 26, 2026

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No know…

CVSS 2.0 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-33673

Published Mar 26, 2026

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An…

CVSS 7.6 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-25597

Published Feb 6, 2026

PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-61924

Published Oct 16, 2025

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from b…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-61923

Published Oct 16, 2025

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the backoffice is missing validation on input resul…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61922

Published Oct 16, 2025

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on th…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-51586

Published Sep 8, 2025

An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password featur…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-25692

Published Jul 30, 2025

A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-25691

Published Jul 30, 2025

A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-36626

Published Nov 29, 2024

In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41651

Published Aug 12, 2024

An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36684

Published Jun 19, 2024

In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-34717

Published May 14, 2024

PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key p…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34716

Published May 14, 2024

PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is pres…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-28392

Published Mar 20, 2024

SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFro…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-25843

Published Feb 27, 2024

In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-26129

Published Feb 19, 2024

PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. A pat…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48926

Published Jan 16, 2024

An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21628

Published Jan 2, 2024

PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possible to store a cross-site scrip…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21627

Published Jan 2, 2024

PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` method. Some modules using the…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47110

Published Nov 9, 2023

blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-47109

Published Nov 8, 2023

PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When adding a block in blockreassu…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43664

Published Sep 28, 2023

PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list all modules without any access rights: method `ajaxProcessGe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43663

Published Sep 28, 2023

PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45448

Published Sep 20, 2023

M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document crafting vulnerability. The resource /m4pdf/pdf.php uses templates…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 128 CVEsPage 1 of 6