Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PrestaShop — Vulnerabilities & Security Advisories 57

All 57 CVE vulnerabilities found in PrestaShop, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities for PrestaShop, an open-source e-commerce platform, focusing on common weakness classes and associated product tags. It collects security advisories and flaw reports for PrestaShop releases, covering the historical range from early public disclosures through the most recent updates. Readers can use this index to track the vendor’s published advisories, analyze the prevalence of specific weakness types such as SQL injection or cross-site scripting, and review the complete vulnerability history for the PrestaShop product line to identify recurring security patterns over time.

Vendor: PrestaShop

CVE ID Title CVSS Severity Published
CVE-2021-21302 CSV Injection via csv export CWE-78 6.8 Medium 2021-02-26
CVE-2020-26224 Improper Access Control in PrestaShop CWE-284 7.5 High 2020-11-16
CVE-2020-15162 Stored XSS in PrestaShop CWE-79 5.4 Medium 2020-09-24
CVE-2020-15160 Blind SQL Injection in PrestaShop CWE-89 9.8 - 2020-09-24
CVE-2020-15161 Potential XSS in PrestaShop CWE-79 5.4 Medium 2020-09-24
CVE-2020-4074 Improper Authentication CWE-287 8.9 High 2020-07-02
CVE-2020-15082 External control of configuration setting in the dashboard in PrestaShop 7.1 High 2020-07-02
CVE-2020-15083 Reflected XSS when uploading an image in the Product page in PrestaShop CWE-79 4.7 Medium 2020-07-02
CVE-2020-11074 Stored XSS in PrestaShop CWE-79 5.4 Medium 2020-07-02
CVE-2020-15079 Improper access control in PrestaShop CWE-284 6.4 Medium 2020-07-02
CVE-2020-15080 Information disclosure in release archive in PrestaShop CWE-200 5.3 Medium 2020-07-02
CVE-2020-15081 Information exposure in the upload directory in PrestaShop CWE-548 5.3 Medium 2020-07-02
CVE-2020-5286 Reflected XSS related in import page in PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5287 Improper access control on customers search in PrestaShop CWE-284 4.1 Medium 2020-04-20
CVE-2020-5288 Improper access control on product attributes page in PrestaShop CWE-284 4.1 Medium 2020-04-20
CVE-2020-5293 Improper access control on product page with combinations, attachments and specific prices in PrestaShop CWE-284 6.5 Medium 2020-04-20
CVE-2020-5271 Reflected XSS with dashboard calendar of PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5272 Reflected XSS on Search page of PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5276 Reflected XSS on AdminCarts page of PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5278 Reflected XSS on Exception page of PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5279 Improper Access Control for certain legacy controller in PrestaShop CWE-284 4.1 Medium 2020-04-20
CVE-2020-5285 Reflected XSS with back parameter in PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5269 Reflected XSS on AdminFeatures page of PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5270 Open redirection when using back parameter of PrestaShop CWE-601 4.1 Medium 2020-04-20
CVE-2020-5264 Reflected XSS in security compromised page of PrestaShop CWE-79 4.4 Medium 2020-04-20
CVE-2020-5265 Reflected XSS on AdminAttributesGroups page of PrestaShop CWE-79 4.4 Medium 2020-04-20
CVE-2020-5250 Possible information disclosure in PrestaShop CWE-285 7.6 High 2020-03-05

All 57 known CVE vulnerabilities affecting PrestaShop with full Chinese analysis, references, and POCs where available.