Vulnerability index

Browse CVEs

113 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-30192 Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find(). Possearchproducts Patch available Fix from $2,3002023-05-12 CRITICAL 9.8 CVE-2023-30194EPSS 32% Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). Poststaticfooter after 1.0.0 Fix from $2,3002023-05-10 HIGH 7.5 CVE-2023-30282 PrestaShop scexportcustomers <= 3.6.1 is vulnerable to Incorrect Access Control. Due to a lack of permissions' control, a guest can access exports fr… Scexportcustomers after 3.6.1 Fix from $1,9502023-05-04 CRITICAL 9.9 CVE-2023-30838 PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop … Prestashop 1.7.8.9 / 8.0.4+ Fix from $2,3002023-04-25 HIGH 8.8 CVE-2023-30839 PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can wri… Prestashop 1.7.8.9 / 8.0.4+ Fix from $1,9502023-04-25 MEDIUM 6.5 CVE-2023-30545 PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, it is possible for a user with access to the SQL Manage… Prestashop 1.7.8.9 / 8.0.4+ Fix from $1,6002023-04-25 CRITICAL 9.8 CVE-2023-27569 The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header. Eo Tags 1.3.0+ Fix from $2,3002023-03-21 CRITICAL 9.8 CVE-2023-27570 The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie. Eo Tags 1.4.19+ Fix from $2,3002023-03-21 HIGH 8.8 CVE-2023-25206 PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection. Advanced Reviews 3.6.2+ Fix from $1,9502023-03-14 CRITICAL 9.8 CVE-2023-25207 PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php. Dpd France 6.1.3+ Fix from $2,3002023-03-13 HIGH 8.8 CVE-2023-25170 PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authen… Prestashop 8.0.1+ Fix from $1,9502023-03-13 HIGH 8.8 CVE-2023-24763 In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0. Xen Forum 2.13.0+ Fix from $1,9502023-03-06 MEDIUM 6.1 CVE-2022-35933 This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an a… Productcomments 5.0.2+ Fix from $1,6002022-09-02 CRITICAL 9.8 CVE-2022-31181EPSS 6% PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerabilit… Prestashop 1.7.8.7+ Fix from $2,3002022-08-01 HIGH 8.8 CVE-2022-31101EPSS 23% prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated cust… Blockwishlist 2.1.1+ Fix from $1,9502022-06-27 CRITICAL 9.8 CVE-2022-21686 PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig c… Prestashop after 1.7.8.3 Fix from $2,3002022-01-26 MEDIUM 6.1 CVE-2012-20001 PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field. Prestashop 1.5.2+ Fix from $1,6002021-12-21 CRITICAL 9.8 CVE-2021-43789 PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search f… Prestashop 1.7.8.2+ Fix from $2,3002021-12-07 MEDIUM 5.4 CVE-2021-21418 ps_emailsubscription is a newsletter subscription module for the PrestaShop platform. An employee can inject javascript in the newsletter condition f… Ps Emailsubscription 2.6.1+ Fix from $1,6002021-03-31 MEDIUM 5.4 CVE-2021-21398 PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can inject HTML when the Grid Colum… Prestashop 1.7.7.3+ Fix from $1,6002021-03-30 CRITICAL 9.1 CVE-2021-21308 PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an atta… Prestashop 1.7.7.2+ Fix from $2,3002021-02-26 HIGH 7.2 CVE-2021-21302 PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by… Prestashop 1.7.7.2+ Fix from $1,9502021-02-26 CRITICAL 9.8 CVE-2021-3110EPSS 21% The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] p… Prestashop No fix yet Fix from $2,3002021-01-20 HIGH 8.2 CVE-2020-26248EPSS 12% In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service… Productcomments 4.2.1+ Fix from $1,9502020-12-03 HIGH 7.5 CVE-2020-26224 In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logged by abusing the function th… Prestashop 1.7.6.9+ Fix from $1,9502020-11-16 MEDIUM 6.1 CVE-2020-26225 In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web browsers by creating a malicious… Product Comments 4.2.0+ Fix from $1,6002020-11-16 CRITICAL 9.8 CVE-2020-15160EPSS 11% PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with loc… Prestashop 1.7.6.8+ Fix from $2,3002020-09-24 MEDIUM 5.4 CVE-2020-15162 In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input… Prestashop 1.7.6.8+ Fix from $1,6002020-09-24 MEDIUM 6.1 CVE-2020-15161 In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is f… Prestashop 1.7.6.8+ Fix from $1,6002020-09-24 CRITICAL 9.3 CVE-2020-15178 In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript while using the contact form… Contactform 4.3.0+ Fix from $2,3002020-09-15