CVEs we hold for Prestashop
Records whose assigning authority named Prestashop as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-92810PrestaShop blockwishlist through 3.0.2 Information DisclosurePrestaShop blockwishlist CVE-2026-92809PrestaShop psgdpr through 1.4.3 GDPR Log ForgeryPrestaShop psgdpr CVE-2026-54159ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCEPrestaShop ps_facetedsearch CVE-2026-44212PrestaShop: Stored XSS executable in customer service viewPrestaShop CVE-2026-33674PrestaShop: Improper Use of Validation FrameworkPrestaShop CVE-2026-33673PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variablesPrestaShop CVE-2026-25597PrestaShop has a time based enumeration in FO login formPrestaShop CVE-2026-14846Incorrect neutralisation in the PrestaShop firmwarePrestaShop The firmware CVE-2025-61924PrestaShop Checkout Target PayPal merchant account hijacking from backofficePrestaShopCorp ps_checkout CVE-2025-61923PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosurePrestaShopCorp ps_checkout CVE-2025-61922PrestaShop Checkout allows customer account takeover via emailPrestaShopCorp ps_checkout CVE-2025-24027ps_contactinfo has potential XSS due to usage of the nofilter tag in templatePrestaShop ps_contactinfo CVE-2025-1230Cross-Site Scripting (XSS) vulnerability in PrestashopPrestashop CVE-2024-34717Anonymous PrestaShop customer can download other customers' invoicesPrestaShop CVE-2024-34716PrestaShop vulnerable to XSS via customer contact form in FO, through file uploadPrestaShop CVE-2024-26129Prestashop vulnerable to path disclosure in JavaScript variablePrestaShop CVE-2024-21628XSS can be stored in DB from "add a message form" in order detail page (FO)PrestaShop CVE-2024-21627Some attribute not escaped in Validate::isCleanHTML methodPrestaShop CVE-2023-47110Any value can be changed in the configuration table by an employee having access to block reassurance modulePrestaShop blockreassurance CVE-2023-47109PrestaShop blockreassurance BO User can remove any file from server when adding a and deleting a blockPrestaShop blockreassurance CVE-2023-43664Employee without any access rights can list all installed modules in PrestashopPrestaShop CVE-2023-39530PrestaShop vulnerable to file deletion via CustomerMessagePrestaShop CVE-2023-39529PrestaShop vulnerable to file deletion via attachment APIPrestaShop CVE-2023-39528PrestaShop vulnerable to file reading through path traversalPrestaShop CVE-2023-39527PrestaShop XSS vulnerability through Validate::isCleanHTML methodPrestaShop CVE-2023-39526PrestaShopSQL manager vulnerability (potential RCE)PrestaShop CVE-2023-39524PrestaShop vulnerable to boolean SQL injection in search product in BOPrestaShop CVE-2023-30839PrestaShop vulnerable to SQL filter bypass leading to arbitrary write requests using "SQL Manager"PrestaShop CVE-2023-30838PrestaShop vulnerable to possible XSS injection through Validate::isCleanHTML methodPrestaShop CVE-2022-46158Potential Information exposure in the upload directory in PrestaShopPrestaShop CVE-2022-45448Cross-site Scripting in M4 PDF plugin for Prestashop sitesPrestashop M4 PDF plugin CVE-2022-45447Path Traversal in M4 PDF plugin for Prestashop sitesPrestashop M4 PDF plugin CVE-2022-35933PrestaShop module Product Comments vulnerable to cross-site scripting (XSS)PrestaShop productcomments CVE-2022-31101SQL Injection in prestashop/blockwishlistPrestaShop blockwishlist CVE-2022-21686Server Side Twig Template Injection in PrestaShopPrestaShop CVE-2021-21418Potential XSS injection in the newsletter conditions fieldPrestaShop ps_emailsubscription CVE-2021-21398Possible XSS injection through DataColumn Grid classPrestaShop CVE-2020-5294Reflected XSS with social networks fieldsPrestaShop ps_socialfollow CVE-2020-5293Improper access control on product page with combinations, attachments and specific prices in PrestaShopPrestaShop CVE-2020-5288Improper access control on product attributes page in PrestaShopPrestaShop CVE-2020-5287Improper access control on customers search in PrestaShopPrestaShop CVE-2020-5286Reflected XSS related in import page in PrestaShopPrestaShop CVE-2020-5285Reflected XSS with back parameter in PrestaShopPrestaShop CVE-2020-5279Improper Access Control for certain legacy controller in PrestaShopPrestaShop CVE-2020-5278Reflected XSS on Exception page of PrestaShopPrestaShop CVE-2020-5277Reflected XSS with url_name parameter of PrestaShop module ps_facetedsearchPrestaShop ps_facetedsearch CVE-2020-5276Reflected XSS on AdminCarts page of PrestaShopPrestaShop CVE-2020-5273Stored XSS with custom URLs in PrestaShop module ps_linklistPrestaShop ps_linklist CVE-2020-5272Reflected XSS on Search page of PrestaShopPrestaShop CVE-2020-5271Reflected XSS with dashboard calendar of PrestaShopPrestaShop CVE-2020-5270Open redirection when using back parameter of PrestaShopPrestaShop CVE-2020-5269Reflected XSS on AdminFeatures page of PrestaShopPrestaShop CVE-2020-5266Stored XSS on back office edit pagePrestaShop ps_linklist CVE-2020-5265Reflected XSS on AdminAttributesGroups page of PrestaShopPrestaShop CVE-2020-5264Reflected XSS in security compromised page of PrestaShopPrestaShop CVE-2020-5250Possible information disclosure in PrestaShopPrestaShop CVE-2020-26248Blind SQL injection during the CommentGrade processPrestaShop productcomments CVE-2020-26225Reflected XSS in PrestaShop Product CommentsPrestaShop productcomments CVE-2020-15178Potential XSS in PrestaShop contactformPrestaShop contactform CVE-2020-15102Improper access control on dashboard form in PrestaShopPrestaShop dashproducts CVE-2020-15083Reflected XSS when uploading an image in the Product page in PrestaShopPrestaShop CVE-2020-15082External control of configuration setting in the dashboard in PrestaShopPrestaShop CVE-2020-15081Information exposure in the upload directory in PrestaShopPrestaShop CVE-2020-15080Information disclosure in release archive in PrestaShopPrestaShop 80 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.