VYPR

Blockwishlist

by Prestashop

Source repositories

CVEs (2)

  • CVE-2022-31101HigJun 27, 2022
    risk 0.51cvss 8.1epss 0.23

    prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds…

  • CVE-2026-92810MedSep 16, 2026
    risk 0.21cvss 4.3epss 0.00

    PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid…