Medium severity4.6NVD Advisory· Published Mar 31, 2021· Updated Jun 17, 2026
CVE-2021-21418
CVE-2021-21418
Description
ps_emailsubscription is a newsletter subscription module for the PrestaShop platform. An employee can inject javascript in the newsletter condition field that will then be executed on the front office The issue has been fixed in 2.6.1
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
prestashop/ps_emailsubscriptionPackagist | < 2.6.1 | 2.6.1 |
Affected products
3< 2.6.1+ 1 more
- (no CPE)range: < 2.6.1
- cpe:2.3:a:prestashop:ps_emailsubscription:*:*:*:*:*:prestashop:*:*range: >=2.6.0,<2.6.1
Patches
Vulnerability mechanics
References
6- github.com/PrestaShop/ps_emailsubscription/commit/664ffb225e2afb4a32640bbedad667dc6e660b70nvdPatchThird Party AdvisoryWEB
- github.com/PrestaShop/ps_emailsubscription/releases/tag/v2.6.1nvdRelease NotesThird Party AdvisoryWEB
- github.com/PrestaShop/ps_emailsubscription/security/advisories/GHSA-vwfx-hh3w-fj99nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-vwfx-hh3w-fj99ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-21418ghsaADVISORY
- packagist.org/packages/prestashop/ps_emailsubscriptionnvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.