Vulnerability index

Browse CVEs

113 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Prestashop MEDIUM 5.4
CVE-2026-33673

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS)…

Fix: 8.2.5 / 9.1.0+
Fix from $1,600 2026-03-26
Prestashop MEDIUM 5.3
CVE-2026-33674

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 an…

Fix: 8.2.5 / 9.1.0+
Fix from $1,600 2026-03-26
Prestashop MEDIUM 5.3
CVE-2026-25597

PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user a…

Fix: 8.2.4 / 9.0.3+
Fix from $1,600 2026-02-06
Prestashop Checkout CRITICAL 9.1
CVE-2025-61922

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5…

Fix: 7.4.4.1 / 7.5.0.5+
Fix from $2,300 2025-10-16
Prestashop MEDIUM 6.5
CVE-2025-25691

A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted PO…

No fix yet
Fix from $1,600 2025-07-30
Prestashop MEDIUM 6.5
CVE-2025-25692

A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST r…

No fix yet
Fix from $1,600 2025-07-30
Prestashop MEDIUM 5.3
CVE-2024-36626

In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.

Patch available
Fix from $1,600 2024-11-29
Prestashop HIGH 8.1
CVE-2024-41651

An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disp…

Fix: after 8.1.7
Fix from $1,950 2024-08-12
Pk Customlinks CRITICAL 9.8
CVE-2024-36684

In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a s…

Fix: after 2.3
Fix from $2,300 2024-06-19
Prestashop MEDIUM 6.1
CVE-2024-34716EPSS 56%

PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-threa…

Fix: 8.1.6+
Fix from $1,600 2024-05-14
Prestashop MEDIUM 5.3
CVE-2024-34717

PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by s…

Mitigation only
Fix from $1,600 2024-05-14
Abandoned Cart Reminder Pro CRITICAL 9.8
CVE-2024-28392

SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproF…

Fix: after 2.0.11
Fix from $2,300 2024-03-20
Import\/update Bulk Product CRITICAL 9.8
CVE-2024-25843

In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can…

Fix: 1.1.29+
Fix from $2,300 2024-02-27
Prestashop MEDIUM 5.3
CVE-2024-26129

PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure i…

Fix: 8.1.4+
Fix from $1,600 2024-02-19
Advanced Loyalty Program MEDIUM 5.3
CVE-2023-48926

An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily chang…

Fix: 2.3.4+
Fix from $1,600 2024-01-16
Prestashop MEDIUM 6.1
CVE-2024-21628

PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possib…

Fix: 8.1.3+
Fix from $1,600 2024-01-02
Prestashop MEDIUM 6.1
CVE-2024-21627

PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` m…

Fix: 1.7.8.11 / 8.1.3+
Fix from $1,600 2024-01-02
Customer Reassurance Block MEDIUM 5.3
CVE-2023-47110

blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax funct…

Fix: 5.1.4+
Fix from $1,600 2023-11-09
Customer Reassurance Block HIGH 8.1
CVE-2023-47109

PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When…

Fix: 5.1.4+
Fix from $1,950 2023-11-08
M4 Pdf MEDIUM 6.1
CVE-2022-45448

M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document crafting vulnerability. The resource…

Fix: after 3.2.3
Fix from $1,600 2023-09-20
M4 Pdf MEDIUM 6.5
CVE-2022-45447

M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerability. The “f” parameter is not p…

Fix: after 3.2.3
Fix from $1,600 2023-09-20
Prestashop CRITICAL 9.8
CVE-2023-39526

PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through…

Fix: 1.7.8.10 / 8.0.5+
Fix from $2,300 2023-08-07
Prestashop CRITICAL 9.1
CVE-2023-39525

PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by…

Fix: 8.1.1+
Fix from $2,300 2023-08-07
Prestashop CRITICAL 9.1
CVE-2023-39529

PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete a file from the server by using the Attachm…

Fix: 8.1.1+
Fix from $2,300 2023-08-07
Prestashop CRITICAL 9.1
CVE-2023-39530

PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessa…

Fix: 8.1.1+
Fix from $2,300 2023-08-07
Prestashop HIGH 8.6
CVE-2023-39528

PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can be used to read any file on th…

Fix: 8.1.1+
Fix from $1,950 2023-08-07
Prestashop MEDIUM 6.1
CVE-2023-39527

PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to cross-site scripting through …

Fix: 1.7.8.10 / 8.0.5+
Fix from $1,600 2023-08-07
Prestashop CRITICAL 9.8
CVE-2023-39524

PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product search field, in BO's product …

Fix: 8.1.1+
Fix from $2,300 2023-08-07
Amazon MEDIUM 5.3
CVE-2023-33777

An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversal attack.

Fix: 5.2.24+
Fix from $1,600 2023-07-25
Payplug CRITICAL 9.8
CVE-2023-30153

An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote…

Fix: 3.8.2+
Fix from $2,300 2023-07-18