Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2026-33673
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS)…
Prestashop
8.2.5 / 9.1.0+
MEDIUM 5.3
CVE-2026-33674
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 an…
Prestashop
8.2.5 / 9.1.0+
MEDIUM 5.3
CVE-2026-25597
PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user a…
Prestashop
8.2.4 / 9.0.3+
CRITICAL 9.1
CVE-2025-61922
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5…
Prestashop Checkout
7.4.4.1 / 7.5.0.5+
MEDIUM 6.5
CVE-2025-25691
A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted PO…
Prestashop
No fix yet
MEDIUM 6.5
CVE-2025-25692
A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST r…
Prestashop
No fix yet
MEDIUM 5.3
CVE-2024-36626
In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.
Prestashop
Patch available
HIGH 8.1
CVE-2024-41651
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disp…
Prestashop
after 8.1.7
CRITICAL 9.8
CVE-2024-36684
In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a s…
Pk Customlinks
after 2.3
MEDIUM 6.1
CVE-2024-34716EPSS 56%
PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-threa…
Prestashop
8.1.6+
MEDIUM 5.3
CVE-2024-34717
PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by s…
Prestashop
Mitigation only
CRITICAL 9.8
CVE-2024-28392
SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproF…
Abandoned Cart Reminder Pro
after 2.0.11
CRITICAL 9.8
CVE-2024-25843
In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can…
Import\/update Bulk Product
1.1.29+
MEDIUM 5.3
CVE-2024-26129
PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure i…
Prestashop
8.1.4+
MEDIUM 5.3
CVE-2023-48926
An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily chang…
Advanced Loyalty Program
2.3.4+
MEDIUM 6.1
CVE-2024-21628
PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possib…
Prestashop
8.1.3+
MEDIUM 6.1
CVE-2024-21627
PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` m…
Prestashop
1.7.8.11 / 8.1.3+
MEDIUM 5.3
CVE-2023-47110
blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax funct…
Customer Reassurance Block
5.1.4+
HIGH 8.1
CVE-2023-47109
PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When…
Customer Reassurance Block
5.1.4+
MEDIUM 6.1
CVE-2022-45448
M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document crafting vulnerability. The resource…
M4 Pdf
after 3.2.3
MEDIUM 6.5
CVE-2022-45447
M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerability. The “f” parameter is not p…
M4 Pdf
after 3.2.3
CRITICAL 9.8
CVE-2023-39526
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through…
Prestashop
1.7.8.10 / 8.0.5+
CRITICAL 9.1
CVE-2023-39525
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by…
Prestashop
8.1.1+
CRITICAL 9.1
CVE-2023-39529
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete a file from the server by using the Attachm…
Prestashop
8.1.1+
CRITICAL 9.1
CVE-2023-39530
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessa…
Prestashop
8.1.1+
HIGH 8.6
CVE-2023-39528
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can be used to read any file on th…
Prestashop
8.1.1+
MEDIUM 6.1
CVE-2023-39527
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to cross-site scripting through …
Prestashop
1.7.8.10 / 8.0.5+
CRITICAL 9.8
CVE-2023-39524
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product search field, in BO's product …
Prestashop
8.1.1+
MEDIUM 5.3
CVE-2023-33777
An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversal attack.
Amazon
5.2.24+
CRITICAL 9.8
CVE-2023-30153
An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote…
Payplug
3.8.2+