VYPR

Prestashop

by Prestashop

Source repositories

CVEs (99)

  • CVE-2018-5682MedJan 13, 2018
    risk 0.35cvss 5.3epss 0.01

    PrestaShop 1.7.2.4 allows user enumeration via the Reset Password feature, by noticing which reset attempts do not produce a "This account does not exist" error message.

  • CVE-2018-5681MedJan 13, 2018
    risk 0.35cvss 5.4epss 0.01

    PrestaShop 1.7.2.4 has XSS via source-code editing on the "Pages > Edit page" screen.

  • CVE-2026-25597MedFeb 6, 2026
    risk 0.34cvss 5.3epss 0.00

    PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in…

  • CVE-2023-43663MedSep 28, 2023
    risk 0.34cvss 6.3epss 0.00

    PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit `ce1f6708` addresses this…

  • CVE-2023-25170MedMar 13, 2023
    risk 0.33cvss 5.0epss 0.00

    PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enable…

  • CVE-2025-1230MedFeb 12, 2025
    risk 0.31cvss 4.8epss 0.00

    Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a specially crafted query…

  • CVE-2024-26129MedFeb 19, 2024
    risk 0.31cvss 5.8epss 0.01

    PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. A patch is available in version 8.1.4.

  • CVE-2020-21967MedJul 13, 2022
    risk 0.31cvss 4.8epss 0.01

    File upload vulnerability in the Catalog feature in Prestashop 1.7.6.7 allows remote attackers to run arbitrary code via the add new file page.

  • CVE-2024-21628MedJan 2, 2024
    risk 0.28cvss 5.4epss 0.00

    PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possible to store a cross-site scripting payload in the database. The impact is low because the HTML is not interpreted in BO, thanks to…

  • CVE-2024-34717MedMay 14, 2024
    risk 0.27cvss 5.3epss 0.01

    PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key parameter in the url. This issue is patched in version 8.1.6. No known workarounds are available.

  • CVE-2022-46158MedDec 8, 2022
    risk 0.27cvss 5.3epss 0.00

    PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem access for users. Users may have been able to view the contents of the upload directory without appropriate permissions. This issue has been addressed and users…

  • CVE-2020-5265MedApr 20, 2020
    risk 0.22cvss 4.4epss 0.01

    In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminAttributesGroups page. The problem is patched in 1.7.6.5.

  • CVE-2020-5264MedApr 20, 2020
    risk 0.22cvss 4.4epss 0.01

    In PrestaShop before version 1.7.6.5, there is a reflected XSS while running the security compromised page. It allows anyone to execute arbitrary action. The problem is patched in the 1.7.6.5.

  • CVE-2023-43664MedSep 28, 2023
    risk 0.21cvss 4.3epss 0.00

    PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list all modules without any access rights: method `ajaxProcessGetPossibleHookingListForModule` doesn't check access rights. This issue has been addressed in commit…

  • CVE-2020-5272MedApr 20, 2020
    risk 0.20cvss 4.1epss 0.01

    In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is a reflected XSS on Search page with `alias` and `search` parameters. The problem is patched in 1.7.6.5

  • CVE-2020-5271MedApr 20, 2020
    risk 0.20cvss 4.1epss 0.01

    In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters in the dashboard page This problem is fixed in 1.7.6.5

  • CVE-2020-5270MedApr 20, 2020
    risk 0.20cvss 4.1epss 0.01

    In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts can be many, and vary from the theft of information and credentials to the redirection to malicious websites containing attacker-controlled content, which in…

  • CVE-2020-5269MedApr 20, 2020
    risk 0.20cvss 4.1epss 0.01

    In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5

  • CVE-2025-51586LowSep 8, 2025
    risk 0.17cvss 3.7epss 0.01

    An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.

  • CVE-2026-33674LowMar 26, 2026
    risk 0.06cvss 2.0epss 0.00

    PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.