Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PrestaShop — Vulnerabilities & Security Advisories 77

Browse all 77 CVE security advisories affecting PrestaShop. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PrestaShop is an open-source e-commerce platform designed for merchants to create and manage online stores. With 71 recorded Common Vulnerabilities and Exposures (CVEs), the software has historically been susceptible to critical security flaws, particularly remote code execution (RCE), cross-site scripting (XSS), and privilege escalation vulnerabilities. These issues often stem from insufficient input validation and improper access controls within its core modules and third-party extensions. Notable incidents include several high-severity RCE exploits that allowed attackers to gain full server control, highlighting risks associated with outdated installations and unpatched third-party plugins. The platform’s modular architecture, while flexible, frequently introduces attack surfaces through poorly secured add-ons. Security advisories emphasize the necessity of regular updates and strict adherence to hardening guidelines to mitigate these persistent threats in production environments.

CVE ID Title CVSS Severity Published
CVE-2026-92810 PrestaShop blockwishlist through 3.0.2 Information Disclosure — blockwishlist CWE-639 4.3 Medium 2026-09-16
CVE-2026-92809 PrestaShop psgdpr through 1.4.3 GDPR Log Forgery — psgdpr CWE-639 4.3 Medium 2026-09-16
CVE-2026-84186 Incorrect access control in PrestaShop — PrestaShop CWE-290 6.9 Medium 2026-09-07
CVE-2026-54159 ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE — ps_facetedsearch CWE-74 10.0 Critical 2026-07-17
CVE-2026-14846 Incorrect neutralisation in the PrestaShop firmware — The firmware CWE-1236 - - 2026-07-13
CVE-2026-44212 PrestaShop: Stored XSS executable in customer service view — PrestaShop CWE-79 9.3 Critical 2026-05-14
CVE-2026-33674 PrestaShop: Improper Use of Validation Framework — PrestaShop CWE-1173 2.0 Low 2026-03-26
CVE-2026-33673 PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables — PrestaShop CWE-79 7.7 High 2026-03-26
CVE-2026-25597 PrestaShop has a time based enumeration in FO login form — PrestaShop CWE-208 5.3 Medium 2026-02-06
CVE-2025-1230 Cross-Site Scripting (XSS) vulnerability in Prestashop — Prestashop CWE-79 4.8 Medium 2025-02-12
CVE-2025-24027 ps_contactinfo has potential XSS due to usage of the nofilter tag in template — ps_contactinfo CWE-79 6.2 Medium 2025-01-22
CVE-2024-34717 Anonymous PrestaShop customer can download other customers' invoices — PrestaShop CWE-200 5.3 Medium 2024-05-14
CVE-2024-34716 PrestaShop vulnerable to XSS via customer contact form in FO, through file upload — PrestaShop CWE-79 9.7 Critical 2024-05-14
CVE-2024-26129 Prestashop vulnerable to path disclosure in JavaScript variable — PrestaShop CWE-22 5.8 Medium 2024-02-19
CVE-2024-21628 XSS can be stored in DB from "add a message form" in order detail page (FO) — PrestaShop CWE-79 5.4 Medium 2024-01-02
CVE-2024-21627 Some attribute not escaped in Validate::isCleanHTML method — PrestaShop CWE-79 8.1 High 2024-01-02
CVE-2023-47110 Any value can be changed in the configuration table by an employee having access to block reassurance module — blockreassurance CWE-284 9.1 Critical 2023-11-09
CVE-2023-47109 PrestaShop blockreassurance BO User can remove any file from server when adding a and deleting a block — blockreassurance CWE-285 5.5 Medium 2023-11-08
CVE-2023-43664 Employee without any access rights can list all installed modules in Prestashop — PrestaShop CWE-269 4.3 Medium 2023-09-28
CVE-2023-43663 Improper Privilege Management in Prestashop — PrestaShop CWE-269 6.3 Medium 2023-09-28
CVE-2022-45448 Cross-site Scripting in M4 PDF plugin for Prestashop sites — M4 PDF plugin CWE-79 3.5 Low 2023-09-20
CVE-2022-45447 Path Traversal in M4 PDF plugin for Prestashop sites — M4 PDF plugin CWE-22 6.5 Medium 2023-09-20
CVE-2023-39530 PrestaShop vulnerable to file deletion via CustomerMessage — PrestaShop CWE-20 6.5 Medium 2023-08-07
CVE-2023-39529 PrestaShop vulnerable to file deletion via attachment API — PrestaShop CWE-20 6.7 Medium 2023-08-07
CVE-2023-39528 PrestaShop vulnerable to file reading through path traversal — PrestaShop CWE-22 6.8 Medium 2023-08-07
CVE-2023-39527 PrestaShop XSS vulnerability through Validate::isCleanHTML method — PrestaShop CWE-79 8.3 High 2023-08-07
CVE-2023-39526 PrestaShopSQL manager vulnerability (potential RCE) — PrestaShop CWE-89 9.1 Critical 2023-08-07
CVE-2023-39525 PrestaShop vulnerable to path traversal — PrestaShop CWE-22 6.5 Medium 2023-08-07
CVE-2023-39524 PrestaShop vulnerable to boolean SQL injection in search product in BO — PrestaShop CWE-89 6.7 Medium 2023-08-07
CVE-2023-30839 PrestaShop vulnerable to SQL filter bypass leading to arbitrary write requests using "SQL Manager" — PrestaShop CWE-89 10.0 Critical 2023-04-25

This page lists every published CVE security advisory associated with PrestaShop. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.