Vulnerability index

Browse CVEs

113 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-33673 PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS)… Prestashop 8.2.5 / 9.1.0+ Fix from $1,6002026-03-26 MEDIUM 5.3 CVE-2026-33674 PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 an… Prestashop 8.2.5 / 9.1.0+ Fix from $1,6002026-03-26 MEDIUM 5.3 CVE-2026-25597 PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user a… Prestashop 8.2.4 / 9.0.3+ Fix from $1,6002026-02-06 CRITICAL 9.1 CVE-2025-61922 PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5… Prestashop Checkout 7.4.4.1 / 7.5.0.5+ Fix from $2,3002025-10-16 MEDIUM 6.5 CVE-2025-25691 A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted PO… Prestashop No fix yet Fix from $1,6002025-07-30 MEDIUM 6.5 CVE-2025-25692 A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST r… Prestashop No fix yet Fix from $1,6002025-07-30 MEDIUM 5.3 CVE-2024-36626 In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php. Prestashop Patch available Fix from $1,6002024-11-29 HIGH 8.1 CVE-2024-41651 An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disp… Prestashop after 8.1.7 Fix from $1,9502024-08-12 CRITICAL 9.8 CVE-2024-36684 In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a s… Pk Customlinks after 2.3 Fix from $2,3002024-06-19 MEDIUM 6.1 CVE-2024-34716EPSS 56% PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-threa… Prestashop 8.1.6+ Fix from $1,6002024-05-14 MEDIUM 5.3 CVE-2024-34717 PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by s… Prestashop Mitigation only Fix from $1,6002024-05-14 CRITICAL 9.8 CVE-2024-28392 SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproF… Abandoned Cart Reminder Pro after 2.0.11 Fix from $2,3002024-03-20 CRITICAL 9.8 CVE-2024-25843 In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can… Import\/update Bulk Product 1.1.29+ Fix from $2,3002024-02-27 MEDIUM 5.3 CVE-2024-26129 PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure i… Prestashop 8.1.4+ Fix from $1,6002024-02-19 MEDIUM 5.3 CVE-2023-48926 An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily chang… Advanced Loyalty Program 2.3.4+ Fix from $1,6002024-01-16 MEDIUM 6.1 CVE-2024-21628 PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possib… Prestashop 8.1.3+ Fix from $1,6002024-01-02 MEDIUM 6.1 CVE-2024-21627 PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` m… Prestashop 1.7.8.11 / 8.1.3+ Fix from $1,6002024-01-02 MEDIUM 5.3 CVE-2023-47110 blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax funct… Customer Reassurance Block 5.1.4+ Fix from $1,6002023-11-09 HIGH 8.1 CVE-2023-47109 PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When… Customer Reassurance Block 5.1.4+ Fix from $1,9502023-11-08 MEDIUM 6.1 CVE-2022-45448 M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document crafting vulnerability. The resource… M4 Pdf after 3.2.3 Fix from $1,6002023-09-20 MEDIUM 6.5 CVE-2022-45447 M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerability. The “f” parameter is not p… M4 Pdf after 3.2.3 Fix from $1,6002023-09-20 CRITICAL 9.8 CVE-2023-39526 PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through… Prestashop 1.7.8.10 / 8.0.5+ Fix from $2,3002023-08-07 CRITICAL 9.1 CVE-2023-39525 PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by… Prestashop 8.1.1+ Fix from $2,3002023-08-07 CRITICAL 9.1 CVE-2023-39529 PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete a file from the server by using the Attachm… Prestashop 8.1.1+ Fix from $2,3002023-08-07 CRITICAL 9.1 CVE-2023-39530 PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessa… Prestashop 8.1.1+ Fix from $2,3002023-08-07 HIGH 8.6 CVE-2023-39528 PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can be used to read any file on th… Prestashop 8.1.1+ Fix from $1,9502023-08-07 MEDIUM 6.1 CVE-2023-39527 PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to cross-site scripting through … Prestashop 1.7.8.10 / 8.0.5+ Fix from $1,6002023-08-07 CRITICAL 9.8 CVE-2023-39524 PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product search field, in BO's product … Prestashop 8.1.1+ Fix from $2,3002023-08-07 MEDIUM 5.3 CVE-2023-33777 An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversal attack. Amazon 5.2.24+ Fix from $1,6002023-07-25 CRITICAL 9.8 CVE-2023-30153 An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote… Payplug 3.8.2+ Fix from $2,3002023-07-18