Vulnerability index

Browse CVEs

113 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2013-4791 PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE. Prestashop 1.4.11+ Fix from $1,6002020-02-14 MEDIUM 6.1 CVE-2012-2517 Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of t… Prestashop 1.4.9.0+ Fix from $1,6002020-02-11 HIGH 8.8 CVE-2013-6358 PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ … Prestashop No fix yet Fix from $1,9502020-01-23 MEDIUM 6.1 CVE-2020-6632 In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/de… Prestashop Patch available Fix from $1,6002020-01-09 CRITICAL 9.8 CVE-2019-19594 reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute… Prestashop No fix yet Fix from $2,3002019-12-05 CRITICAL 9.8 CVE-2019-19595 reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers… Prestashop No fix yet Fix from $2,3002019-12-05 HIGH 7.5 CVE-2019-13461 In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulne… Prestashop after 1.7.5.2 Fix from $1,9502019-07-09 MEDIUM 6.1 CVE-2019-11876 In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation b… Prestashop No fix yet Fix from $1,6002019-05-24 HIGH 8.8 CVE-2018-20717 In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the rights of … Prestashop 1.7.2.5+ Fix from $1,9502019-01-15 CRITICAL 9.8 CVE-2018-19355 modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute … Prestashop after 1.7.0.0 Fix from $2,3002018-11-19 CRITICAL 9.8 CVE-2018-19126EPSS 23% PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload. Prestashop 1.6.1.23 / 1.7.4.4+ Fix from $2,3002018-11-09 HIGH 7.5 CVE-2018-19124 PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 on Windows allows remote attackers to write to arbitrary image files. Prestashop 1.6.1.23 / 1.7.4.4+ Fix from $1,9502018-11-09 HIGH 7.5 CVE-2018-19125EPSS 11% PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory. Prestashop 1.6.1.23 / 1.7.4.4+ Fix from $1,9502018-11-09 CRITICAL 9.1 CVE-2018-13784EPSS 17% PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php. Prestashop 1.6.1.20 / 1.7.3.4+ Fix from $2,3002018-07-09 HIGH 7.5 CVE-2018-7491 In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user… Prestashop after 1.7.2.5 Fix from $1,9502018-02-26 MEDIUM 5.4 CVE-2018-5681 PrestaShop 1.7.2.4 has XSS via source-code editing on the "Pages > Edit page" screen. Prestashop Mitigation only Fix from $1,6002018-01-13 MEDIUM 5.3 CVE-2018-5682 PrestaShop 1.7.2.4 allows user enumeration via the Reset Password feature, by noticing which reset attempts do not produce a "This account does not e… Prestashop Mitigation only Fix from $1,6002018-01-13 MEDIUM 5.8 CVE-2012-5801 The PayPal module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fi… Ebay No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5799 The Canada Post (aka CanadaPost) module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN… Prestashop No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5800 The eBay module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fiel… Ebay Module No fix yet Fix from $1,6002012-11-04 MEDIUM 5.0 CVE-2011-4545 CRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTT… Prestashop No fix yet Fix from $1,6002011-12-02 MEDIUM 5.0 CVE-2011-3796 PrestaShop 1.4.0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path i… Prestashop Mitigation only Fix from $1,6002011-09-24 HIGH 10.0 CVE-2008-5791 Multiple unspecified vulnerabilities in PrestaShop e-Commerce Solution before 1.1 Beta 2 (aka 1.1.0.1) have unknown impact and attack vectors, relate… Prestashop after 1.0 Fix from $1,9502008-12-31