| CVE-2026-44212 |
critical |
9.3 |
9.3 |
19d ago |
PrestaShop has a stored XSS executable in customer service view |
|
| CVE-2026-33673 |
unknown |
— |
— |
2mo ago |
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables |
|
| CVE-2026-33674 |
unknown |
— |
— |
2mo ago |
PrestaShop: Improper Use of Validation Framework |
|
| CVE-2026-25597 |
unknown |
— |
— |
4mo ago |
PrestaShop affected by time based enumeration in FO login form |
|
| CVE-2025-51586 |
unknown |
— |
— |
9mo ago |
Presta Shop vulnerable to email enumeration |
|
| CVE-2024-34717 |
unknown |
— |
— |
2y ago |
Anonymous PrestaShop customer can download other customers' invoices |
|
| CVE-2024-34716 |
unknown |
— |
— |
2y ago |
PrestaShop cross-site scripting via customer contact form in FO, through file upload |
|
| CVE-2024-26129 |
unknown |
— |
— |
2y ago |
Path disclosure in JavaScript variable |
|
| CVE-2024-21628 |
unknown |
— |
— |
2y ago |
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO) |
|
| CVE-2024-21627 |
unknown |
— |
— |
2y ago |
PrestaShop some attribute not escaped in Validate::isCleanHTML method |
|
| CVE-2023-43663 |
unknown |
— |
— |
3y ago |
PrestaShop allows users to uninstall modules from backoffice, even with low rights |
|
| CVE-2023-43664 |
unknown |
— |
— |
3y ago |
PrestaShop allows employee without any access rights to list all installed modules |
|
| CVE-2023-39530 |
unknown |
— |
— |
3y ago |
PrestaShop file deletion via CustomerMessage |
|
| CVE-2023-39529 |
unknown |
— |
— |
3y ago |
PrestaShop file deletion via attachment API |
|
| CVE-2023-39528 |
unknown |
— |
— |
3y ago |
PrestaShop file access through path traversal |
|
| CVE-2023-39527 |
unknown |
— |
— |
3y ago |
PrestaShop XSS injection through Validate::isCleanHTML method |
|
| CVE-2023-39526 |
unknown |
— |
— |
3y ago |
PrestaShop SQL manager vulnerability |
|
| CVE-2023-39525 |
unknown |
— |
— |
3y ago |
PrestaShop path traversal |
|
| CVE-2023-39524 |
unknown |
— |
— |
3y ago |
PrestaShop boolean SQL injection |
|
| CVE-2023-30545 |
unknown |
— |
— |
3y ago |
Arbitrary file read via SQL injection |
|
| CVE-2023-30838 |
unknown |
— |
— |
3y ago |
Possible XSS injection through Validate::isCleanHTML method |
|
| CVE-2023-30839 |
unknown |
— |
— |
3y ago |
SQL filter bypass leading to arbitrary write requests using "SQL Manager" |
|
| CVE-2023-25170 |
unknown |
— |
— |
3y ago |
Possible CSRF token fixation |
|
| CVE-2022-46158 |
unknown |
— |
— |
4y ago |
PrestaShop has potential Information exposure in the upload directory |
|
| CVE-2022-31181 |
unknown |
— |
— |
4y ago |
PrestaShop eval injection possible if shop vulnerable to SQL injection |
|
| CVE-2019-11876 |
unknown |
— |
— |
4y ago |
PrestaShop Cross-site Scripting vulnerability |
|
| CVE-2018-20717 |
unknown |
— |
— |
4y ago |
PrestaShop PHP Object Injection |
|
| CVE-2013-4791 |
unknown |
— |
— |
4y ago |
PrestaShop Stored Cross-Site Scripting Vulnerability |
|
| CVE-2012-20001 |
unknown |
— |
— |
4y ago |
PrestaShop XSS Vulnerability |
|
| CVE-2022-21686 |
unknown |
— |
— |
4y ago |
Server Side Twig Template Injection |
|
| CVE-2021-43789 |
unknown |
— |
— |
5y ago |
SQL injection in prestashop/prestashop |
|