VYPR
Vendor

Prestashop

Products
183
CVEs
217
Across products
151
Status
Private

Products

183
View all 183 products →

Recent CVEs

217
View all 217 CVEs →
  • CVE-2023-27034CriMar 23, 2023
    risk 0.68cvss 9.8epss 0.59

    PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.

  • CVE-2018-8823CriMar 28, 2018
    risk 0.68cvss 9.8epss 0.51

    modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter.

  • CVE-2023-30194CriMay 10, 2023
    risk 0.66cvss 9.8epss 0.32

    Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().

  • CVE-2023-50029CriJun 24, 2024
    risk 0.65cvss 10.0epss 0.01

    PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaShop allows attackers to run arbitrary code via the M4PDF::saveTemplate() method.

  • CVE-2021-3110CriJan 20, 2021
    risk 0.65cvss 9.8epss 0.21

    The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.

  • CVE-2018-10942CriMay 10, 2018
    risk 0.65cvss 9.8epss 0.13

    modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.

  • CVE-2025-69633CriFeb 13, 2026
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup…

  • CVE-2024-34989CriJun 21, 2024
    risk 0.64cvss 9.8epss 0.00

    In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injection via `PrestaPDFProductListModuleFrontController::queryDb().'

  • CVE-2024-36684CriJun 19, 2024
    risk 0.64cvss 9.8epss 0.00

    In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.

  • CVE-2024-33269CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Prestaddons flashsales 1.9.7 and before allows an attacker to run arbitrary SQL commands via the FsModel::getFlashSales method.

  • CVE-2024-28393CriMar 25, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the ScalapayReturnModuleFrontController::postProcess() method.

  • CVE-2024-28392CriMar 20, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method.

  • CVE-2024-28391CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and…

  • CVE-2024-28390CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sensitive information via Improper Access Control.

  • CVE-2024-28388CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.

  • CVE-2024-25849CriMar 8, 2024
    risk 0.64cvss 9.8epss 0.01

    In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` .

  • CVE-2024-25843CriFeb 27, 2024
    risk 0.64cvss 9.8epss 0.01

    In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions.

  • CVE-2023-46350CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods…

  • CVE-2023-50061CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher().

  • CVE-2024-24303CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModuleFrontController::addGif…