Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PrestaShop — Vulnerabilities & Security Advisories 77

Browse all 77 CVE security advisories affecting PrestaShop. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PrestaShop is an open-source e-commerce platform designed for merchants to create and manage online stores. With 71 recorded Common Vulnerabilities and Exposures (CVEs), the software has historically been susceptible to critical security flaws, particularly remote code execution (RCE), cross-site scripting (XSS), and privilege escalation vulnerabilities. These issues often stem from insufficient input validation and improper access controls within its core modules and third-party extensions. Notable incidents include several high-severity RCE exploits that allowed attackers to gain full server control, highlighting risks associated with outdated installations and unpatched third-party plugins. The platform’s modular architecture, while flexible, frequently introduces attack surfaces through poorly secured add-ons. Security advisories emphasize the necessity of regular updates and strict adherence to hardening guidelines to mitigate these persistent threats in production environments.

CVE ID Title CVSS Severity Published
CVE-2023-30838 PrestaShop vulnerable to possible XSS injection through Validate::isCleanHTML method — PrestaShop CWE-79 8.6 High 2023-04-25
CVE-2023-30545 PrestaShop arbitrary file read vulnerability — PrestaShop CWE-89 7.7 High 2023-04-25
CVE-2023-25170 PrestaShop has possible CSRF token fixation — PrestaShop CWE-352 5.0 Medium 2023-03-13
CVE-2022-46158 Potential Information exposure in the upload directory in PrestaShop — PrestaShop CWE-200 5.3 Medium 2022-12-08
CVE-2022-35933 PrestaShop module Product Comments vulnerable to cross-site scripting (XSS) — productcomments CWE-79 7.2 - 2022-09-02
CVE-2022-31181 Remote code execution in prestashop — PrestaShop CWE-89 9.8 Critical 2022-08-01
CVE-2022-31101 SQL Injection in prestashop/blockwishlist — blockwishlist CWE-89 8.1 High 2022-06-27
CVE-2022-21686 Server Side Twig Template Injection in PrestaShop — PrestaShop CWE-94 9.0 Critical 2022-01-26
CVE-2021-43789 Blind SQLi using Search filters in PrestaShop — PrestaShop CWE-89 7.5 High 2021-12-07
CVE-2021-21418 Potential XSS injection in the newsletter conditions field — ps_emailsubscription CWE-79 4.6 Medium 2021-03-31
CVE-2021-21398 Possible XSS injection through DataColumn Grid class — PrestaShop CWE-79 5.4 Medium 2021-03-30
CVE-2021-21308 Improper session management for soft logout — PrestaShop CWE-287 6.1 Medium 2021-02-26
CVE-2021-21302 CSV Injection via csv export — PrestaShop CWE-78 6.8 Medium 2021-02-26
CVE-2020-26248 Blind SQL injection during the CommentGrade process — productcomments CWE-89 6.8 Medium 2020-12-03
CVE-2020-26225 Reflected XSS in PrestaShop Product Comments — productcomments CWE-79 8.7 High 2020-11-16
CVE-2020-26224 Improper Access Control in PrestaShop — PrestaShop CWE-284 7.5 High 2020-11-16
CVE-2020-15162 Stored XSS in PrestaShop — PrestaShop CWE-79 5.4 Medium 2020-09-24
CVE-2020-15160 Blind SQL Injection in PrestaShop — PrestaShop CWE-89 9.8 - 2020-09-24
CVE-2020-15161 Potential XSS in PrestaShop — PrestaShop CWE-79 5.4 Medium 2020-09-24
CVE-2020-15178 Potential XSS in PrestaShop contactform — contactform CWE-79 8.0 High 2020-09-15
CVE-2020-15102 Improper access control on dashboard form in PrestaShop — dashproducts CWE-284 6.5 Medium 2020-07-21
CVE-2020-4074 Improper Authentication — PrestaShop CWE-287 8.9 High 2020-07-02
CVE-2020-15082 External control of configuration setting in the dashboard in PrestaShop — PrestaShop 7.1 High 2020-07-02
CVE-2020-15083 Reflected XSS when uploading an image in the Product page in PrestaShop — PrestaShop CWE-79 4.7 Medium 2020-07-02
CVE-2020-11074 Stored XSS in PrestaShop — PrestaShop CWE-79 5.4 Medium 2020-07-02
CVE-2020-15079 Improper access control in PrestaShop — PrestaShop CWE-284 6.4 Medium 2020-07-02
CVE-2020-15080 Information disclosure in release archive in PrestaShop — PrestaShop CWE-200 5.3 Medium 2020-07-02
CVE-2020-15081 Information exposure in the upload directory in PrestaShop — PrestaShop CWE-548 5.3 Medium 2020-07-02
CVE-2020-5286 Reflected XSS related in import page in PrestaShop — PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5287 Improper access control on customers search in PrestaShop — PrestaShop CWE-284 4.1 Medium 2020-04-20

This page lists every published CVE security advisory associated with PrestaShop. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.