Prestashop
by Prestashop
Source repositories
CVEs (99)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-5682 | Med | 0.35 | 5.3 | 0.01 | Jan 13, 2018 | PrestaShop 1.7.2.4 allows user enumeration via the Reset Password feature, by noticing which reset attempts do not produce a "This account does not exist" error message. | ||
| CVE-2018-5681 | Med | 0.35 | 5.4 | 0.01 | Jan 13, 2018 | PrestaShop 1.7.2.4 has XSS via source-code editing on the "Pages > Edit page" screen. | ||
| CVE-2026-25597 | Med | 0.34 | 5.3 | 0.00 | Feb 6, 2026 | PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in… | ||
| CVE-2023-43663 | Med | 0.34 | 6.3 | 0.00 | Sep 28, 2023 | PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit `ce1f6708` addresses this… | ||
| CVE-2023-25170 | Med | 0.33 | 5.0 | 0.00 | Mar 13, 2023 | PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enable… | ||
| CVE-2025-1230 | Med | 0.31 | 4.8 | 0.00 | Feb 12, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a specially crafted query… | ||
| CVE-2024-26129 | Med | 0.31 | 5.8 | 0.01 | Feb 19, 2024 | PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. A patch is available in version 8.1.4. | ||
| CVE-2020-21967 | Med | 0.31 | 4.8 | 0.01 | Jul 13, 2022 | File upload vulnerability in the Catalog feature in Prestashop 1.7.6.7 allows remote attackers to run arbitrary code via the add new file page. | ||
| CVE-2024-21628 | Med | 0.28 | 5.4 | 0.00 | Jan 2, 2024 | PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possible to store a cross-site scripting payload in the database. The impact is low because the HTML is not interpreted in BO, thanks to… | ||
| CVE-2024-34717 | Med | 0.27 | 5.3 | 0.01 | May 14, 2024 | PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key parameter in the url. This issue is patched in version 8.1.6. No known workarounds are available. | ||
| CVE-2022-46158 | Med | 0.27 | 5.3 | 0.00 | Dec 8, 2022 | PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem access for users. Users may have been able to view the contents of the upload directory without appropriate permissions. This issue has been addressed and users… | ||
| CVE-2020-5265 | Med | 0.22 | 4.4 | 0.01 | Apr 20, 2020 | In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminAttributesGroups page. The problem is patched in 1.7.6.5. | ||
| CVE-2020-5264 | Med | 0.22 | 4.4 | 0.01 | Apr 20, 2020 | In PrestaShop before version 1.7.6.5, there is a reflected XSS while running the security compromised page. It allows anyone to execute arbitrary action. The problem is patched in the 1.7.6.5. | ||
| CVE-2023-43664 | Med | 0.21 | 4.3 | 0.00 | Sep 28, 2023 | PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list all modules without any access rights: method `ajaxProcessGetPossibleHookingListForModule` doesn't check access rights. This issue has been addressed in commit… | ||
| CVE-2020-5272 | Med | 0.20 | 4.1 | 0.01 | Apr 20, 2020 | In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is a reflected XSS on Search page with `alias` and `search` parameters. The problem is patched in 1.7.6.5 | ||
| CVE-2020-5271 | Med | 0.20 | 4.1 | 0.01 | Apr 20, 2020 | In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters in the dashboard page This problem is fixed in 1.7.6.5 | ||
| CVE-2020-5270 | Med | 0.20 | 4.1 | 0.01 | Apr 20, 2020 | In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts can be many, and vary from the theft of information and credentials to the redirection to malicious websites containing attacker-controlled content, which in… | ||
| CVE-2020-5269 | Med | 0.20 | 4.1 | 0.01 | Apr 20, 2020 | In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5 | ||
| CVE-2025-51586 | Low | 0.17 | 3.7 | 0.01 | Sep 8, 2025 | An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature. | ||
| CVE-2026-33674 | Low | 0.06 | 2.0 | 0.00 | Mar 26, 2026 | PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available. |
- risk 0.35cvss 5.3epss 0.01
PrestaShop 1.7.2.4 allows user enumeration via the Reset Password feature, by noticing which reset attempts do not produce a "This account does not exist" error message.
- risk 0.35cvss 5.4epss 0.01
PrestaShop 1.7.2.4 has XSS via source-code editing on the "Pages > Edit page" screen.
- risk 0.34cvss 5.3epss 0.00
PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in…
- risk 0.34cvss 6.3epss 0.00
PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit `ce1f6708` addresses this…
- risk 0.33cvss 5.0epss 0.00
PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enable…
- risk 0.31cvss 4.8epss 0.00
Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a specially crafted query…
- risk 0.31cvss 5.8epss 0.01
PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. A patch is available in version 8.1.4.
- risk 0.31cvss 4.8epss 0.01
File upload vulnerability in the Catalog feature in Prestashop 1.7.6.7 allows remote attackers to run arbitrary code via the add new file page.
- risk 0.28cvss 5.4epss 0.00
PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possible to store a cross-site scripting payload in the database. The impact is low because the HTML is not interpreted in BO, thanks to…
- risk 0.27cvss 5.3epss 0.01
PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key parameter in the url. This issue is patched in version 8.1.6. No known workarounds are available.
- risk 0.27cvss 5.3epss 0.00
PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem access for users. Users may have been able to view the contents of the upload directory without appropriate permissions. This issue has been addressed and users…
- risk 0.22cvss 4.4epss 0.01
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminAttributesGroups page. The problem is patched in 1.7.6.5.
- risk 0.22cvss 4.4epss 0.01
In PrestaShop before version 1.7.6.5, there is a reflected XSS while running the security compromised page. It allows anyone to execute arbitrary action. The problem is patched in the 1.7.6.5.
- risk 0.21cvss 4.3epss 0.00
PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list all modules without any access rights: method `ajaxProcessGetPossibleHookingListForModule` doesn't check access rights. This issue has been addressed in commit…
- risk 0.20cvss 4.1epss 0.01
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is a reflected XSS on Search page with `alias` and `search` parameters. The problem is patched in 1.7.6.5
- risk 0.20cvss 4.1epss 0.01
In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters in the dashboard page This problem is fixed in 1.7.6.5
- risk 0.20cvss 4.1epss 0.01
In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts can be many, and vary from the theft of information and credentials to the redirection to malicious websites containing attacker-controlled content, which in…
- risk 0.20cvss 4.1epss 0.01
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5
- risk 0.17cvss 3.7epss 0.01
An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.
- risk 0.06cvss 2.0epss 0.00
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.
Page 3 of 5