VYPR

Vendor CVEs

Prestashop

All CVEs

217 total · sorted by risk
  • CVE-2023-27034CriMar 23, 2023
    risk 0.68cvss 9.8epss 0.59

    PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.

  • CVE-2018-8823CriMar 28, 2018
    risk 0.68cvss 9.8epss 0.51

    modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter.

  • CVE-2023-30194CriMay 10, 2023
    risk 0.66cvss 9.8epss 0.32

    Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().

  • CVE-2023-50029CriJun 24, 2024
    risk 0.65cvss 10.0epss 0.01

    PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaShop allows attackers to run arbitrary code via the M4PDF::saveTemplate() method.

  • CVE-2021-3110CriJan 20, 2021
    risk 0.65cvss 9.8epss 0.21

    The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.

  • CVE-2018-10942CriMay 10, 2018
    risk 0.65cvss 9.8epss 0.13

    modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.

  • CVE-2025-69633CriFeb 13, 2026
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup…

  • CVE-2024-34989CriJun 21, 2024
    risk 0.64cvss 9.8epss 0.00

    In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injection via `PrestaPDFProductListModuleFrontController::queryDb().'

  • CVE-2024-36684CriJun 19, 2024
    risk 0.64cvss 9.8epss 0.00

    In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.

  • CVE-2024-33269CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Prestaddons flashsales 1.9.7 and before allows an attacker to run arbitrary SQL commands via the FsModel::getFlashSales method.

  • CVE-2024-28393CriMar 25, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the ScalapayReturnModuleFrontController::postProcess() method.

  • CVE-2024-28392CriMar 20, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method.

  • CVE-2024-28391CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and…

  • CVE-2024-28390CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sensitive information via Improper Access Control.

  • CVE-2024-28388CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.

  • CVE-2024-25849CriMar 8, 2024
    risk 0.64cvss 9.8epss 0.01

    In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` .

  • CVE-2024-25843CriFeb 27, 2024
    risk 0.64cvss 9.8epss 0.01

    In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions.

  • CVE-2023-46350CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods…

  • CVE-2023-50061CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher().

  • CVE-2024-24303CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModuleFrontController::addGif…

  • CVE-2023-46914CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via ics_export.php.

  • CVE-2023-50028CriJan 19, 2024
    risk 0.64cvss 9.8epss 0.01

    In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL injection.

  • CVE-2023-50027CriJan 5, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() method.

  • CVE-2023-48188CriNov 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in PrestaShop opartdevis v.4.5.18 thru v.4.6.12 allows a remote attacker to execute arbitrary code via a crafted script to the getModuleTranslation function.

  • CVE-2023-46349CriNov 27, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpdateModel::getExportIds()` has sensitive SQL calls that can be executed with a trivial http call and…

  • CVE-2023-45377CriNov 22, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Chronopost Official" (chronopost) for PrestaShop, a guest can perform SQL injection. The script PHP `cancelSkybill.php` own a sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

  • CVE-2023-45387CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection via `exportProduct::_addDataToDb().`

  • CVE-2023-36263CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.00

    Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection. OpartlimitquantityAlertlimitModuleFrontController::displayAjaxPushAlertMessage()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

  • CVE-2023-27846CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop themevolty v.4.0.8 and before allow a remote attacker to gain privileges via the tvcmsblog, tvcmsvideotab, tvcmswishlist, tvcmsbrandlist, tvcmscategorychainslider, tvcmscategoryproduct, tvcmscategoryslider, tvcmspaymenticon,…

  • CVE-2023-30154CriOct 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Multiple improper neutralization of SQL parameters in module AfterMail (aftermailpresta) for PrestaShop, before version 2.2.1, allows remote attackers to perform SQL injection attacks via `id_customer`, `id_conf`, `id_product` and `token` parameters in `aftermailajax.php via the…

  • CVE-2023-34576CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in updatepos.php in PrestaShop opartfaq through 1.0.3 allows remote attackers to run arbitrary SQL commands via unspedified vector.

  • CVE-2023-34577CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Prestashop opartplannedpopup 1.4.11 and earlier allows remote attackers to run arbitrary SQL commands via OpartPlannedPopupModuleFrontController::prepareHook() method.

  • CVE-2023-39675CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.

  • CVE-2023-34575CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL commands via OpartSaveCartDefaultModuleFrontController::initContent() and OpartSaveCartDefaultModuleFrontController::displayAjaxSendCartByEmail() methods.

  • CVE-2023-39643CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xmlfeeds().

  • CVE-2023-33663CriAug 16, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can perform SQL injection up to 0.2.0. Release 0.2.1 fixed this security issue.

  • CVE-2023-33493CriAug 1, 2023
    risk 0.64cvss 9.8epss 0.01

    An Unrestricted Upload of File with Dangerous Type vulnerability in the Ajaxmanager File and Database explorer (ajaxmanager) module for PrestaShop through 2.3.0, allows remote attackers to upload dangerous files without restrictions.

  • CVE-2023-26859CriJul 26, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privileges via the ajaxOrderTracking.php component.

  • CVE-2023-30153CriJul 18, 2023
    risk 0.64cvss 9.8epss 0.01

    An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote attackers to execute arbitrary SQL commands via the ajax.php front controller.

  • CVE-2023-30151CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in the Boxtal (envoimoinscher) module for PrestaShop, after version 3.1.10, allows remote attackers to execute arbitrary SQL commands via the `key` GET parameter.

  • CVE-2023-27845CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop lekerawen_ocs before v.1.4.1 allow a remote attacker to gain privileges via the KerawenHelper::setCartOperationInfo, and KerawenHelper::resetCheckoutSessionData components.

  • CVE-2023-31672CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    In the PrestaShop < 2.4.3 module "Length, weight or volume sell" (ailinear) there is a SQL injection vulnerability.

  • CVE-2023-30150CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.

  • CVE-2023-31671CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess().

  • CVE-2023-29632CriJun 6, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php.

  • CVE-2023-29631CriJun 5, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.

  • CVE-2023-29630CriJun 5, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php.

  • CVE-2023-29629CriJun 5, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop jmsthemelayout 2.5.5 is vulnerable to SQL Injection via ajax_jmsvermegamenu.php.

  • CVE-2023-33280CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.

  • CVE-2023-33279CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.

Page 1 of 5