Vulnerability index

Browse CVEs

113 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Prestashop MEDIUM 5.4
CVE-2013-4791

PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.

Fix: 1.4.11+
Fix from $1,600 2020-02-14
Prestashop MEDIUM 6.1
CVE-2012-2517

Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of t…

Fix: 1.4.9.0+
Fix from $1,600 2020-02-11
Prestashop HIGH 8.8
CVE-2013-6358

PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ …

No fix yet
Fix from $1,950 2020-01-23
Prestashop MEDIUM 6.1
CVE-2020-6632

In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/de…

Patch available
Fix from $1,600 2020-01-09
Prestashop CRITICAL 9.8
CVE-2019-19594

reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute…

No fix yet
Fix from $2,300 2019-12-05
Prestashop CRITICAL 9.8
CVE-2019-19595

reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers…

No fix yet
Fix from $2,300 2019-12-05
Prestashop HIGH 7.5
CVE-2019-13461

In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulne…

Fix: after 1.7.5.2
Fix from $1,950 2019-07-09
Prestashop MEDIUM 6.1
CVE-2019-11876

In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation b…

No fix yet
Fix from $1,600 2019-05-24
Prestashop HIGH 8.8
CVE-2018-20717

In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the rights of …

Fix: 1.7.2.5+
Fix from $1,950 2019-01-15
Prestashop CRITICAL 9.8
CVE-2018-19355

modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute …

Fix: after 1.7.0.0
Fix from $2,300 2018-11-19
Prestashop CRITICAL 9.8
CVE-2018-19126EPSS 23%

PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.

Fix: 1.6.1.23 / 1.7.4.4+
Fix from $2,300 2018-11-09
Prestashop HIGH 7.5
CVE-2018-19124

PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 on Windows allows remote attackers to write to arbitrary image files.

Fix: 1.6.1.23 / 1.7.4.4+
Fix from $1,950 2018-11-09
Prestashop HIGH 7.5
CVE-2018-19125EPSS 11%

PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory.

Fix: 1.6.1.23 / 1.7.4.4+
Fix from $1,950 2018-11-09
Prestashop CRITICAL 9.1
CVE-2018-13784EPSS 17%

PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.

Fix: 1.6.1.20 / 1.7.3.4+
Fix from $2,300 2018-07-09
Prestashop HIGH 7.5
CVE-2018-7491

In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user…

Fix: after 1.7.2.5
Fix from $1,950 2018-02-26
Prestashop MEDIUM 5.4
CVE-2018-5681

PrestaShop 1.7.2.4 has XSS via source-code editing on the "Pages > Edit page" screen.

Mitigation only
Fix from $1,600 2018-01-13
Prestashop MEDIUM 5.3
CVE-2018-5682

PrestaShop 1.7.2.4 allows user enumeration via the Reset Password feature, by noticing which reset attempts do not produce a "This account does not e…

Mitigation only
Fix from $1,600 2018-01-13
Ebay MEDIUM 5.8
CVE-2012-5801

The PayPal module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fi…

No fix yet
Fix from $1,600 2012-11-04
Prestashop MEDIUM 5.8
CVE-2012-5799

The Canada Post (aka CanadaPost) module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN…

No fix yet
Fix from $1,600 2012-11-04
Ebay Module MEDIUM 5.8
CVE-2012-5800

The eBay module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fiel…

No fix yet
Fix from $1,600 2012-11-04
Prestashop MEDIUM 5.0
CVE-2011-4545

CRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTT…

No fix yet
Fix from $1,600 2011-12-02
Prestashop MEDIUM 5.0
CVE-2011-3796

PrestaShop 1.4.0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path i…

Mitigation only
Fix from $1,600 2011-09-24
Prestashop HIGH 10.0
CVE-2008-5791

Multiple unspecified vulnerabilities in PrestaShop e-Commerce Solution before 1.1 Beta 2 (aka 1.1.0.1) have unknown impact and attack vectors, relate…

Fix: after 1.0
Fix from $1,950 2008-12-31