VYPR

Prestashop

by Prestashop

Source repositories

CVEs (99)

  • CVE-2020-4074HigJul 2, 2020
    risk 0.51cvss 8.9epss 0.02

    In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6.

  • CVE-2019-13461HigJul 9, 2019
    risk 0.49cvss 7.5epss 0.02

    In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulnerability due to a guessable value sent to the web application during checkout. An attacker could leak personal customer…

  • CVE-2023-30838HigApr 25, 2023
    risk 0.48cvss 8.5epss 0.01

    PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop misses hijackable events which can lead to cross-site scripting (XSS) injection, allowed by the presence of pre-setup `@keyframes`…

  • CVE-2023-39527HigAug 7, 2023
    risk 0.47cvss 8.3epss 0.01

    PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to cross-site scripting through the `isCleanHTML` method. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.

  • CVE-2024-21627HigJan 2, 2024
    risk 0.46cvss 8.1epss 0.01

    PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` method. Some modules using the `isCleanHTML` method could be vulnerable to cross-site scripting. Versions 8.1.3 and 1.7.8.11…

  • CVE-2023-30545HigApr 25, 2023
    risk 0.43cvss 7.7epss 0.01

    PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, it is possible for a user with access to the SQL Manager (Advanced Options -> Database) to arbitrarily read any file on the operating system when using SQL function `LOAD_FILE` in a…

  • CVE-2012-2517MedFeb 11, 2020
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.

  • CVE-2026-33673HigMar 26, 2026
    risk 0.42cvss 7.6epss 0.00

    PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-office access or a previously…

  • CVE-2025-25692MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.01

    A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2025-25691MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.01

    A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2021-43789HigDec 7, 2021
    risk 0.42cvss 7.5epss 0.05

    PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search filters with `orderBy` and `sortOrder` parameters. The problem is fixed in version 1.7.8.2.

  • CVE-2012-20001MedDec 21, 2021
    risk 0.40cvss 6.1epss 0.01

    PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.

  • CVE-2019-11876MedMay 24, 2019
    risk 0.40cvss 6.1epss 0.01

    In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing…

  • CVE-2023-39529MedAug 7, 2023
    risk 0.37cvss 6.7epss 0.01

    PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete a file from the server by using the Attachments controller and the Attachments API. Version 8.1.1 contains a patch for this issue. There are no known workarounds.

  • CVE-2023-39528MedAug 7, 2023
    risk 0.37cvss 6.8epss 0.01

    PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can be used to read any file on the server, potentially even outside of the project if the server is not correctly configured. Version 8.1.1 contains a patch for…

  • CVE-2023-39524MedAug 7, 2023
    risk 0.37cvss 6.7epss 0.01

    PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product search field, in BO's product page. Version 8.1.1 contains a patch for this issue. There are no known workarounds.

  • CVE-2013-4792MedFeb 14, 2020
    risk 0.36cvss 5.5epss 0.00

    PrestaShop before 1.4.11 allows logout CSRF.

  • CVE-2023-39530MedAug 7, 2023
    risk 0.35cvss 6.5epss 0.01

    PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessage API. Version 8.1.1 contains a patch for this issue. There are no known workarounds.

  • CVE-2023-39525MedAug 7, 2023
    risk 0.35cvss 6.5epss 0.01

    PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path that uses the traversal path. Version 8.1.1 contains a patch…

  • CVE-2013-4791MedFeb 14, 2020
    risk 0.35cvss 5.4epss 0.01

    PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.

Page 2 of 5