Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PrestaShop — Vulnerabilities & Security Advisories 77

Browse all 77 CVE security advisories affecting PrestaShop. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PrestaShop is an open-source e-commerce platform designed for merchants to create and manage online stores. With 71 recorded Common Vulnerabilities and Exposures (CVEs), the software has historically been susceptible to critical security flaws, particularly remote code execution (RCE), cross-site scripting (XSS), and privilege escalation vulnerabilities. These issues often stem from insufficient input validation and improper access controls within its core modules and third-party extensions. Notable incidents include several high-severity RCE exploits that allowed attackers to gain full server control, highlighting risks associated with outdated installations and unpatched third-party plugins. The platform’s modular architecture, while flexible, frequently introduces attack surfaces through poorly secured add-ons. Security advisories emphasize the necessity of regular updates and strict adherence to hardening guidelines to mitigate these persistent threats in production environments.

Found 57 results / 77 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2021-21302 CSV Injection via csv export — PrestaShop CWE-78 6.8 Medium 2021-02-26
CVE-2020-26224 Improper Access Control in PrestaShop — PrestaShop CWE-284 7.5 High 2020-11-16
CVE-2020-15162 Stored XSS in PrestaShop — PrestaShop CWE-79 5.4 Medium 2020-09-24
CVE-2020-15160 Blind SQL Injection in PrestaShop — PrestaShop CWE-89 9.8 - 2020-09-24
CVE-2020-15161 Potential XSS in PrestaShop — PrestaShop CWE-79 5.4 Medium 2020-09-24
CVE-2020-4074 Improper Authentication — PrestaShop CWE-287 8.9 High 2020-07-02
CVE-2020-15082 External control of configuration setting in the dashboard in PrestaShop — PrestaShop 7.1 High 2020-07-02
CVE-2020-15083 Reflected XSS when uploading an image in the Product page in PrestaShop — PrestaShop CWE-79 4.7 Medium 2020-07-02
CVE-2020-11074 Stored XSS in PrestaShop — PrestaShop CWE-79 5.4 Medium 2020-07-02
CVE-2020-15079 Improper access control in PrestaShop — PrestaShop CWE-284 6.4 Medium 2020-07-02
CVE-2020-15080 Information disclosure in release archive in PrestaShop — PrestaShop CWE-200 5.3 Medium 2020-07-02
CVE-2020-15081 Information exposure in the upload directory in PrestaShop — PrestaShop CWE-548 5.3 Medium 2020-07-02
CVE-2020-5286 Reflected XSS related in import page in PrestaShop — PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5287 Improper access control on customers search in PrestaShop — PrestaShop CWE-284 4.1 Medium 2020-04-20
CVE-2020-5288 Improper access control on product attributes page in PrestaShop — PrestaShop CWE-284 4.1 Medium 2020-04-20
CVE-2020-5293 Improper access control on product page with combinations, attachments and specific prices in PrestaShop — PrestaShop CWE-284 6.5 Medium 2020-04-20
CVE-2020-5271 Reflected XSS with dashboard calendar of PrestaShop — PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5272 Reflected XSS on Search page of PrestaShop — PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5276 Reflected XSS on AdminCarts page of PrestaShop — PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5278 Reflected XSS on Exception page of PrestaShop — PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5279 Improper Access Control for certain legacy controller in PrestaShop — PrestaShop CWE-284 4.1 Medium 2020-04-20
CVE-2020-5285 Reflected XSS with back parameter in PrestaShop — PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5269 Reflected XSS on AdminFeatures page of PrestaShop — PrestaShop CWE-79 4.1 Medium 2020-04-20
CVE-2020-5270 Open redirection when using back parameter of PrestaShop — PrestaShop CWE-601 4.1 Medium 2020-04-20
CVE-2020-5264 Reflected XSS in security compromised page of PrestaShop — PrestaShop CWE-79 4.4 Medium 2020-04-20
CVE-2020-5265 Reflected XSS on AdminAttributesGroups page of PrestaShop — PrestaShop CWE-79 4.4 Medium 2020-04-20
CVE-2020-5250 Possible information disclosure in PrestaShop — PrestaShop CWE-285 7.6 High 2020-03-05

This page lists every published CVE security advisory associated with PrestaShop. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.