Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Prestashop MEDIUM 6.5
CVE-2025-25691

A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted PO…

No fix yet
Fix from $1,600 2025-07-30
Prestashop MEDIUM 6.5
CVE-2025-25692

A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST r…

No fix yet
Fix from $1,600 2025-07-30
Prestashop MEDIUM 5.3
CVE-2024-34717

PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by s…

Mitigation only
Fix from $1,600 2024-05-14
Prestashop CRITICAL 9.8
CVE-2021-3110EPSS 21%

The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] p…

No fix yet
Fix from $2,300 2021-01-20
Prestashop CRITICAL 9.8
CVE-2013-6295

PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module

No fix yet
Fix from $2,300 2020-02-18
Prestashop HIGH 8.8
CVE-2013-6358

PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ …

No fix yet
Fix from $1,950 2020-01-23
Prestashop CRITICAL 9.8
CVE-2019-19594

reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute…

No fix yet
Fix from $2,300 2019-12-05
Prestashop CRITICAL 9.8
CVE-2019-19595

reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers…

No fix yet
Fix from $2,300 2019-12-05
Prestashop MEDIUM 6.1
CVE-2019-11876

In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation b…

No fix yet
Fix from $1,600 2019-05-24
Prestashop MEDIUM 5.4
CVE-2018-5681

PrestaShop 1.7.2.4 has XSS via source-code editing on the "Pages > Edit page" screen.

Mitigation only
Fix from $1,600 2018-01-13
Prestashop MEDIUM 5.3
CVE-2018-5682

PrestaShop 1.7.2.4 allows user enumeration via the Reset Password feature, by noticing which reset attempts do not produce a "This account does not e…

Mitigation only
Fix from $1,600 2018-01-13
Ebay MEDIUM 5.8
CVE-2012-5801

The PayPal module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fi…

No fix yet
Fix from $1,600 2012-11-04
Prestashop MEDIUM 5.8
CVE-2012-5799

The Canada Post (aka CanadaPost) module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN…

No fix yet
Fix from $1,600 2012-11-04
Ebay Module MEDIUM 5.8
CVE-2012-5800

The eBay module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fiel…

No fix yet
Fix from $1,600 2012-11-04
Prestashop MEDIUM 5.0
CVE-2011-4545

CRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTT…

No fix yet
Fix from $1,600 2011-12-02
Prestashop MEDIUM 5.0
CVE-2011-3796

PrestaShop 1.4.0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path i…

Mitigation only
Fix from $1,600 2011-09-24