VYPR

Prestashop

by Prestashop

Source repositories

CVEs (99)

  • CVE-2018-19126CriNov 9, 2018
    risk 0.05cvss 9.8epss 0.23

    PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.

  • CVE-2018-19125HigNov 9, 2018
    risk 0.04cvss 7.5epss 0.11

    PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory.

  • CVE-2018-13784CriJul 9, 2018
    risk 0.04cvss 9.1epss 0.17

    PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.

  • CVE-2011-4545Dec 2, 2011
    risk 0.03cvss epss 0.04

    CRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the name parameter.

  • CVE-2011-4544Dec 1, 2011
    risk 0.03cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Prestashop before 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) address or (2) relativ_base_dir parameter to modules/mondialrelay/googlemap.php; the (3) relativ_base_dir, (4) Pays, (5) Ville,…

  • CVE-2008-6503Mar 20, 2009
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in PrestaShop 1.1.0.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin/login.php and (2) order.php.

  • CVE-2026-14846MedJul 13, 2026
    risk 0.00cvss epss 0.00

    In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation of the ‘Alias’ parameter in the ‘Update your address’ function. This flaw allows an attacker to inject malicious expressions that…

  • CVE-2024-36626MedNov 29, 2024
    risk 0.00cvss 5.3epss 0.01

    In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.

  • CVE-2021-21398MedMar 30, 2021
    risk 0.00cvss 5.4epss 0.01

    PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can inject HTML when the Grid Column Type DataColumn is badly used. The problem is fixed in 1.7.7.3

  • CVE-2021-21308MedFeb 26, 2021
    risk 0.00cvss 6.1epss 0.01

    PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an attacker is able to foreign request and executes customer commands. The problem is fixed in 1.7.7.2

  • CVE-2021-21302MedFeb 26, 2021
    risk 0.00cvss 6.8epss 0.01

    PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2

  • CVE-2020-26224HigNov 16, 2020
    risk 0.00cvss 7.5epss 0.02

    In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logged by abusing the function that allows a shopping cart to be recreated from an order already placed. The problem is fixed in 1.7.6.9.

  • CVE-2020-15162MedSep 24, 2020
    risk 0.00cvss 5.4epss 0.01

    In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input malicious JavaScript which triggered an XSS payload. The problem is fixed in version 1.7.6.8.

  • CVE-2020-15161MedSep 24, 2020
    risk 0.00cvss 5.4epss 0.01

    In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8

  • CVE-2020-15083MedJul 2, 2020
    risk 0.00cvss 4.7epss 0.01

    In PrestaShop from version 1.7.0.0 and before version 1.7.6.6, if a target sends a corrupted file, it leads to a reflected XSS. The problem is fixed in 1.7.6.6

  • CVE-2020-15082HigJul 2, 2020
    risk 0.00cvss 7.1epss 0.01

    In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the dashboard allows rewriting all configuration variables. The problem is fixed in 1.7.6.6

  • CVE-2020-15081MedJul 2, 2020
    risk 0.00cvss 5.3epss 0.02

    In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The problem is fixed in version 1.7.6.6. A possible workaround is to add an empty index.php file in the upload directory.

  • CVE-2020-15080MedJul 2, 2020
    risk 0.00cvss 5.3epss 0.01

    In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. The problem is fixed in version 1.7.6.6 A possible workaround is to make sure `composer.json` and `docker-compose.yml` are not…

  • CVE-2020-15079MedJul 2, 2020
    risk 0.00cvss 6.4epss 0.01

    In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6

  • CVE-2020-11074MedJul 2, 2020
    risk 0.00cvss 5.4epss 0.01

    In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick access item. The problem is fixed in 1.7.6.6.

Page 4 of 5