Vulnerability index

Browse CVEs

113 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2020-15102 In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The … Dashboard Products 2.1.0+ Fix from $1,6002020-07-21 CRITICAL 9.8 CVE-2020-4074 In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and e… Prestashop 1.7.6.6+ Fix from $2,3002020-07-02 HIGH 8.8 CVE-2020-15082 In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the dashboard allows rewriting all configuration variables. The problem is fixed in 1.… Prestashop 1.7.6.6+ Fix from $1,9502020-07-02 MEDIUM 6.1 CVE-2020-15083 In PrestaShop from version 1.7.0.0 and before version 1.7.6.6, if a target sends a corrupted file, it leads to a reflected XSS. The problem is fixed … Prestashop 1.7.6.6+ Fix from $1,6002020-07-02 MEDIUM 5.4 CVE-2020-11074 In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick access item. The problem is fixed… Prestashop 1.7.6.6+ Fix from $1,6002020-07-02 MEDIUM 5.4 CVE-2020-15079 In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions.… Prestashop 1.7.6.6+ Fix from $1,6002020-07-02 MEDIUM 5.3 CVE-2020-15080 In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. … Prestashop 1.7.6.6+ Fix from $1,6002020-07-02 MEDIUM 5.3 CVE-2020-15081 In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The problem is fixed in version 1.7.6.6… Prestashop 1.7.6.6+ Fix from $1,6002020-07-02 HIGH 7.5 CVE-2020-12120 The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password … Correos Express after 1.7 Fix from $1,9502020-04-27 MEDIUM 6.5 CVE-2020-5287 In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5. Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.5 CVE-2020-5288 "In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The problem is fixed in 1.7.6.5. Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.5 CVE-2020-5293 In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific pr… Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.1 CVE-2020-5285 In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is a reflected XSS with `back` parameter. The problem is fixed in 1.7.6.5 Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.1 CVE-2020-5286 In PrestaShop between versions 1.7.4.0 and 1.7.6.5, there is a reflected XSS when uploading a wrong file. The problem is fixed in 1.7.6.5 Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.5 CVE-2020-5279 In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-d… Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.1 CVE-2020-5264 In PrestaShop before version 1.7.6.5, there is a reflected XSS while running the security compromised page. It allows anyone to execute arbitrary act… Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.1 CVE-2020-5265 In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminAttributesGroups page. The problem is patched in 1.7.6.5. Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.1 CVE-2020-5269 In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem i… Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.1 CVE-2020-5270 In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts can be many, and vary from th… Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.1 CVE-2020-5271 In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters in the dashboard page This pro… Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.1 CVE-2020-5272 In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is a reflected XSS on Search page with `alias` and `search` parameters. The problem is patc… Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.1 CVE-2020-5276 In PrestaShop between versions 1.7.1.0 and 1.7.6.5, there is a reflected XSS on AdminCarts page with `cartBox` parameter The problem is fixed in 1.7.… Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.1 CVE-2020-5278 In PrestaShop between versions 1.5.4.0 and 1.7.6.5, there is a reflected XSS on Exception page The problem is fixed in 1.7.6.5 Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 5.4 CVE-2020-5266 In the ps_link module for PrestaShop before version 3.1.0, there is a stored XSS when you create or edit a link list block with the title field. The … Prestashop Link 3.1.0+ Fix from $1,6002020-04-16 MEDIUM 5.4 CVE-2020-5273 In PrestaShop module ps_linklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fixed in version 3.1.0 Prestashop Linklist 3.1.0+ Fix from $1,6002020-04-16 MEDIUM 5.4 CVE-2020-5294 PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflected XSS with social networks fields The problem is fixed in 2.1.0 Prestashop Socialfollow 2.1.0+ Fix from $1,6002020-04-16 MEDIUM 5.4 CVE-2020-5277 PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with `url_name` parameter. The problem is fixed in 3.5.0 Faceted Search Module 3.5.0+ Fix from $1,6002020-03-25 MEDIUM 6.3 CVE-2020-5250 In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone … Prestashop 1.7.6.4+ Fix from $1,6002020-03-05 CRITICAL 9.8 CVE-2013-6295 PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module Prestashop No fix yet Fix from $2,3002020-02-18 MEDIUM 5.5 CVE-2013-4792 PrestaShop before 1.4.11 allows logout CSRF. Prestashop 1.4.11+ Fix from $1,6002020-02-14