Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2023-30192
Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().
Possearchproducts
Patch available
CRITICAL 9.8
CVE-2023-30194EPSS 32%
Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().
Poststaticfooter
after 1.0.0
HIGH 7.5
CVE-2023-30282
PrestaShop scexportcustomers <= 3.6.1 is vulnerable to Incorrect Access Control. Due to a lack of permissions' control, a guest can access exports fr…
Scexportcustomers
after 3.6.1
CRITICAL 9.9
CVE-2023-30838
PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop …
Prestashop
1.7.8.9 / 8.0.4+
HIGH 8.8
CVE-2023-30839
PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can wri…
Prestashop
1.7.8.9 / 8.0.4+
MEDIUM 6.5
CVE-2023-30545
PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, it is possible for a user with access to the SQL Manage…
Prestashop
1.7.8.9 / 8.0.4+
CRITICAL 9.8
CVE-2023-27569
The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.
Eo Tags
1.3.0+
CRITICAL 9.8
CVE-2023-27570
The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.
Eo Tags
1.4.19+
HIGH 8.8
CVE-2023-25206
PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.
Advanced Reviews
3.6.2+
CRITICAL 9.8
CVE-2023-25207
PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.
Dpd France
6.1.3+
HIGH 8.8
CVE-2023-25170
PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authen…
Prestashop
8.0.1+
HIGH 8.8
CVE-2023-24763
In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0.
Xen Forum
2.13.0+
MEDIUM 6.1
CVE-2022-35933
This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an a…
Productcomments
5.0.2+
CRITICAL 9.8
CVE-2022-31181EPSS 6%
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerabilit…
Prestashop
1.7.8.7+
HIGH 8.8
CVE-2022-31101EPSS 23%
prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated cust…
Blockwishlist
2.1.1+
CRITICAL 9.8
CVE-2022-21686
PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig c…
Prestashop
after 1.7.8.3
MEDIUM 6.1
CVE-2012-20001
PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.
Prestashop
1.5.2+
CRITICAL 9.8
CVE-2021-43789
PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search f…
Prestashop
1.7.8.2+
MEDIUM 5.4
CVE-2021-21418
ps_emailsubscription is a newsletter subscription module for the PrestaShop platform. An employee can inject javascript in the newsletter condition f…
Ps Emailsubscription
2.6.1+
MEDIUM 5.4
CVE-2021-21398
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can inject HTML when the Grid Colum…
Prestashop
1.7.7.3+
CRITICAL 9.1
CVE-2021-21308
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an atta…
Prestashop
1.7.7.2+
HIGH 7.2
CVE-2021-21302
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by…
Prestashop
1.7.7.2+
CRITICAL 9.8
CVE-2021-3110EPSS 21%
The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] p…
Prestashop
No fix yet
HIGH 8.2
CVE-2020-26248EPSS 12%
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service…
Productcomments
4.2.1+
HIGH 7.5
CVE-2020-26224
In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logged by abusing the function th…
Prestashop
1.7.6.9+
MEDIUM 6.1
CVE-2020-26225
In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web browsers by creating a malicious…
Product Comments
4.2.0+
CRITICAL 9.8
CVE-2020-15160EPSS 11%
PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with loc…
Prestashop
1.7.6.8+
MEDIUM 5.4
CVE-2020-15162
In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input…
Prestashop
1.7.6.8+
MEDIUM 6.1
CVE-2020-15161
In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is f…
Prestashop
1.7.6.8+
CRITICAL 9.3
CVE-2020-15178
In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript while using the contact form…
Contactform
4.3.0+