Medium severity5.8NVD Advisory· Published Feb 19, 2024· Updated Jun 17, 2026
CVE-2024-26129
CVE-2024-26129
Description
PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. A patch is available in version 8.1.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
prestashop/prestashopPackagist | >= 8.1.0, < 8.1.4 | 8.1.4 |
Affected products
4cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*range: >=8.1.0,<8.1.4
- (no CPE)range: >= 8.1.0, < 8.1.4
- osv-coords2 versions
>= 8.1.0, < 8.1.5+ 1 more
- (no CPE)range: >= 8.1.0, < 8.1.5
- (no CPE)range: >= 8.1.0, < 8.1.4
Patches
Vulnerability mechanics
References
5- github.com/PrestaShop/PrestaShop/commit/444bd0dea581659918fe2067541b9863cf099dd5nvdPatchWEB
- github.com/PrestaShop/PrestaShop/security/advisories/GHSA-3366-9287-7qprnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-3366-9287-7qprghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-26129ghsaADVISORY
- owasp.org/www-community/attacks/Full_Path_DisclosurenvdNot ApplicableWEB
News mentions
0No linked articles in our index yet.