vciy

CVEs we hold for Prestashop

Records whose assigning authority named Prestashop as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-92810PrestaShop blockwishlist through 3.0.2 Information DisclosurePrestaShop blockwishlist
CVE-2026-92809PrestaShop psgdpr through 1.4.3 GDPR Log ForgeryPrestaShop psgdpr
CVE-2026-84186Incorrect access control in PrestaShopPrestaShop
CVE-2026-54159ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCEPrestaShop ps_facetedsearch
CVE-2026-44212PrestaShop: Stored XSS executable in customer service viewPrestaShop
CVE-2026-33674PrestaShop: Improper Use of Validation FrameworkPrestaShop
CVE-2026-33673PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variablesPrestaShop
CVE-2026-25597PrestaShop has a time based enumeration in FO login formPrestaShop
CVE-2026-14846Incorrect neutralisation in the PrestaShop firmwarePrestaShop The firmware
CVE-2025-61924PrestaShop Checkout Target PayPal merchant account hijacking from backofficePrestaShopCorp ps_checkout
CVE-2025-61923PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosurePrestaShopCorp ps_checkout
CVE-2025-61922PrestaShop Checkout allows customer account takeover via emailPrestaShopCorp ps_checkout
CVE-2025-24027ps_contactinfo has potential XSS due to usage of the nofilter tag in templatePrestaShop ps_contactinfo
CVE-2025-1230Cross-Site Scripting (XSS) vulnerability in PrestashopPrestashop
CVE-2024-34717Anonymous PrestaShop customer can download other customers' invoicesPrestaShop
CVE-2024-34716PrestaShop vulnerable to XSS via customer contact form in FO, through file uploadPrestaShop
CVE-2024-26129Prestashop vulnerable to path disclosure in JavaScript variablePrestaShop
CVE-2024-21628XSS can be stored in DB from "add a message form" in order detail page (FO)PrestaShop
CVE-2024-21627Some attribute not escaped in Validate::isCleanHTML methodPrestaShop
CVE-2023-47110Any value can be changed in the configuration table by an employee having access to block reassurance modulePrestaShop blockreassurance
CVE-2023-47109PrestaShop blockreassurance BO User can remove any file from server when adding a and deleting a blockPrestaShop blockreassurance
CVE-2023-43664Employee without any access rights can list all installed modules in PrestashopPrestaShop
CVE-2023-43663Improper Privilege Management in PrestashopPrestaShop
CVE-2023-39530PrestaShop vulnerable to file deletion via CustomerMessagePrestaShop
CVE-2023-39529PrestaShop vulnerable to file deletion via attachment APIPrestaShop
CVE-2023-39528PrestaShop vulnerable to file reading through path traversalPrestaShop
CVE-2023-39527PrestaShop XSS vulnerability through Validate::isCleanHTML methodPrestaShop
CVE-2023-39526PrestaShopSQL manager vulnerability (potential RCE)PrestaShop
CVE-2023-39525PrestaShop vulnerable to path traversalPrestaShop
CVE-2023-39524PrestaShop vulnerable to boolean SQL injection in search product in BOPrestaShop
CVE-2023-30839PrestaShop vulnerable to SQL filter bypass leading to arbitrary write requests using "SQL Manager"PrestaShop
CVE-2023-30838PrestaShop vulnerable to possible XSS injection through Validate::isCleanHTML methodPrestaShop
CVE-2023-30545PrestaShop arbitrary file read vulnerabilityPrestaShop
CVE-2023-25170PrestaShop has possible CSRF token fixationPrestaShop
CVE-2022-46158Potential Information exposure in the upload directory in PrestaShopPrestaShop
CVE-2022-45448Cross-site Scripting in M4 PDF plugin for Prestashop sitesPrestashop M4 PDF plugin
CVE-2022-45447Path Traversal in M4 PDF plugin for Prestashop sitesPrestashop M4 PDF plugin
CVE-2022-35933PrestaShop module Product Comments vulnerable to cross-site scripting (XSS)PrestaShop productcomments
CVE-2022-31181Remote code execution in prestashopPrestaShop
CVE-2022-31101SQL Injection in prestashop/blockwishlistPrestaShop blockwishlist
CVE-2022-21686Server Side Twig Template Injection in PrestaShopPrestaShop
CVE-2021-43789Blind SQLi using Search filters in PrestaShopPrestaShop
CVE-2021-21418Potential XSS injection in the newsletter conditions fieldPrestaShop ps_emailsubscription
CVE-2021-21398Possible XSS injection through DataColumn Grid classPrestaShop
CVE-2021-21308Improper session management for soft logoutPrestaShop
CVE-2021-21302CSV Injection via csv exportPrestaShop
CVE-2020-5294Reflected XSS with social networks fieldsPrestaShop ps_socialfollow
CVE-2020-5293Improper access control on product page with combinations, attachments and specific prices in PrestaShopPrestaShop
CVE-2020-5288Improper access control on product attributes page in PrestaShopPrestaShop
CVE-2020-5287Improper access control on customers search in PrestaShopPrestaShop
CVE-2020-5286Reflected XSS related in import page in PrestaShopPrestaShop
CVE-2020-5285Reflected XSS with back parameter in PrestaShopPrestaShop
CVE-2020-5279Improper Access Control for certain legacy controller in PrestaShopPrestaShop
CVE-2020-5278Reflected XSS on Exception page of PrestaShopPrestaShop
CVE-2020-5277Reflected XSS with url_name parameter of PrestaShop module ps_facetedsearchPrestaShop ps_facetedsearch
CVE-2020-5276Reflected XSS on AdminCarts page of PrestaShopPrestaShop
CVE-2020-5273Stored XSS with custom URLs in PrestaShop module ps_linklistPrestaShop ps_linklist
CVE-2020-5272Reflected XSS on Search page of PrestaShopPrestaShop
CVE-2020-5271Reflected XSS with dashboard calendar of PrestaShopPrestaShop
CVE-2020-5270Open redirection when using back parameter of PrestaShopPrestaShop
CVE-2020-5269Reflected XSS on AdminFeatures page of PrestaShopPrestaShop
CVE-2020-5266Stored XSS on back office edit pagePrestaShop ps_linklist
CVE-2020-5265Reflected XSS on AdminAttributesGroups page of PrestaShopPrestaShop
CVE-2020-5264Reflected XSS in security compromised page of PrestaShopPrestaShop
CVE-2020-5250Possible information disclosure in PrestaShopPrestaShop
CVE-2020-4074Improper AuthenticationPrestaShop
CVE-2020-26248Blind SQL injection during the CommentGrade processPrestaShop productcomments
CVE-2020-26225Reflected XSS in PrestaShop Product CommentsPrestaShop productcomments
CVE-2020-26224Improper Access Control in PrestaShopPrestaShop
CVE-2020-15178Potential XSS in PrestaShop contactformPrestaShop contactform
CVE-2020-15162Stored XSS in PrestaShopPrestaShop
CVE-2020-15161Potential XSS in PrestaShopPrestaShop
CVE-2020-15160Blind SQL Injection in PrestaShopPrestaShop
CVE-2020-15102Improper access control on dashboard form in PrestaShopPrestaShop dashproducts
CVE-2020-15083Reflected XSS when uploading an image in the Product page in PrestaShopPrestaShop
CVE-2020-15082External control of configuration setting in the dashboard in PrestaShopPrestaShop
CVE-2020-15081Information exposure in the upload directory in PrestaShopPrestaShop
CVE-2020-15080Information disclosure in release archive in PrestaShopPrestaShop
CVE-2020-15079Improper access control in PrestaShopPrestaShop
CVE-2020-11074Stored XSS in PrestaShopPrestaShop

80 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.