Medium severity4.4NVD Advisory· Published Apr 16, 2020· Updated Jun 17, 2026
CVE-2020-5266
CVE-2020-5266
Description
In the ps_link module for PrestaShop before version 3.1.0, there is a stored XSS when you create or edit a link list block with the title field. The problem is fixed in 3.1.0
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:prestashop:prestashop_link:*:*:*:*:*:prestashop:*:*Range: >=1.0.4,<3.1.0
<3.1.0+ 1 more
- (no CPE)range: <3.1.0
- (no CPE)range: < 3.1.0
Patches
Vulnerability mechanics
References
2- github.com/PrestaShop/ps_linklist/commit/b90005c2cfed949ab564228b277a728e0a62a876nvdPatchThird Party Advisory
- github.com/PrestaShop/ps_linklist/security/advisories/GHSA-vr7g-vqp5-966jnvdThird Party Advisory
News mentions
0No linked articles in our index yet.