Vulnerability index

Browse CVEs

113 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Possearchproducts CRITICAL 9.8
CVE-2023-30192

Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().

Patch available
Fix from $2,300 2023-05-12
Poststaticfooter CRITICAL 9.8
CVE-2023-30194EPSS 32%

Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().

Fix: after 1.0.0
Fix from $2,300 2023-05-10
Scexportcustomers HIGH 7.5
CVE-2023-30282

PrestaShop scexportcustomers <= 3.6.1 is vulnerable to Incorrect Access Control. Due to a lack of permissions' control, a guest can access exports fr…

Fix: after 3.6.1
Fix from $1,950 2023-05-04
Prestashop CRITICAL 9.9
CVE-2023-30838

PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop …

Fix: 1.7.8.9 / 8.0.4+
Fix from $2,300 2023-04-25
Prestashop HIGH 8.8
CVE-2023-30839

PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can wri…

Fix: 1.7.8.9 / 8.0.4+
Fix from $1,950 2023-04-25
Prestashop MEDIUM 6.5
CVE-2023-30545

PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, it is possible for a user with access to the SQL Manage…

Fix: 1.7.8.9 / 8.0.4+
Fix from $1,600 2023-04-25
Eo Tags CRITICAL 9.8
CVE-2023-27569

The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.

Fix: 1.3.0+
Fix from $2,300 2023-03-21
Eo Tags CRITICAL 9.8
CVE-2023-27570

The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.

Fix: 1.4.19+
Fix from $2,300 2023-03-21
Advanced Reviews HIGH 8.8
CVE-2023-25206

PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.

Fix: 3.6.2+
Fix from $1,950 2023-03-14
Dpd France CRITICAL 9.8
CVE-2023-25207

PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.

Fix: 6.1.3+
Fix from $2,300 2023-03-13
Prestashop HIGH 8.8
CVE-2023-25170

PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authen…

Fix: 8.0.1+
Fix from $1,950 2023-03-13
Xen Forum HIGH 8.8
CVE-2023-24763

In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0.

Fix: 2.13.0+
Fix from $1,950 2023-03-06
Productcomments MEDIUM 6.1
CVE-2022-35933

This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an a…

Fix: 5.0.2+
Fix from $1,600 2022-09-02
Prestashop CRITICAL 9.8
CVE-2022-31181EPSS 6%

PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerabilit…

Fix: 1.7.8.7+
Fix from $2,300 2022-08-01
Blockwishlist HIGH 8.8
CVE-2022-31101EPSS 23%

prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated cust…

Fix: 2.1.1+
Fix from $1,950 2022-06-27
Prestashop CRITICAL 9.8
CVE-2022-21686

PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig c…

Fix: after 1.7.8.3
Fix from $2,300 2022-01-26
Prestashop MEDIUM 6.1
CVE-2012-20001

PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.

Fix: 1.5.2+
Fix from $1,600 2021-12-21
Prestashop CRITICAL 9.8
CVE-2021-43789

PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search f…

Fix: 1.7.8.2+
Fix from $2,300 2021-12-07
Ps Emailsubscription MEDIUM 5.4
CVE-2021-21418

ps_emailsubscription is a newsletter subscription module for the PrestaShop platform. An employee can inject javascript in the newsletter condition f…

Fix: 2.6.1+
Fix from $1,600 2021-03-31
Prestashop MEDIUM 5.4
CVE-2021-21398

PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can inject HTML when the Grid Colum…

Fix: 1.7.7.3+
Fix from $1,600 2021-03-30
Prestashop CRITICAL 9.1
CVE-2021-21308

PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an atta…

Fix: 1.7.7.2+
Fix from $2,300 2021-02-26
Prestashop HIGH 7.2
CVE-2021-21302

PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by…

Fix: 1.7.7.2+
Fix from $1,950 2021-02-26
Prestashop CRITICAL 9.8
CVE-2021-3110EPSS 21%

The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] p…

No fix yet
Fix from $2,300 2021-01-20
Productcomments HIGH 8.2
CVE-2020-26248EPSS 12%

In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service…

Fix: 4.2.1+
Fix from $1,950 2020-12-03
Prestashop HIGH 7.5
CVE-2020-26224

In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logged by abusing the function th…

Fix: 1.7.6.9+
Fix from $1,950 2020-11-16
Product Comments MEDIUM 6.1
CVE-2020-26225

In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web browsers by creating a malicious…

Fix: 4.2.0+
Fix from $1,600 2020-11-16
Prestashop CRITICAL 9.8
CVE-2020-15160EPSS 11%

PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with loc…

Fix: 1.7.6.8+
Fix from $2,300 2020-09-24
Prestashop MEDIUM 5.4
CVE-2020-15162

In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input…

Fix: 1.7.6.8+
Fix from $1,600 2020-09-24
Prestashop MEDIUM 6.1
CVE-2020-15161

In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is f…

Fix: 1.7.6.8+
Fix from $1,600 2020-09-24
Contactform CRITICAL 9.3
CVE-2020-15178

In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript while using the contact form…

Fix: 4.3.0+
Fix from $2,300 2020-09-15