📦 Prestashop

by Prestashop

🔍 What is Prestashop?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-34716

CRITICAL CVSS 9.6 May 14, 2024

This is a stored cross-site scripting (XSS) vulnerability in PrestaShop that allows attackers to upload malicious files through the contact form. When an administrator opens the infected attachment in...

CVE-2023-39526

CRITICAL CVSS 9.1 Aug 7, 2023

This CVE allows attackers to execute arbitrary code on PrestaShop e-commerce platforms through SQL injection and arbitrary file write vulnerabilities in the back office. Attackers can gain full contro...

CVE-2023-30839

CRITICAL CVSS 9.9 Apr 25, 2023

This CVE describes a SQL injection vulnerability in PrestaShop e-commerce software that allows back-office users to perform unauthorized database operations. Users with back-office access can write, u...

CVE-2022-21686

CRITICAL CVSS 9.0 Jan 26, 2022

This vulnerability allows attackers to inject Twig template code into the PrestaShop back office when using legacy layouts. Successful exploitation could lead to remote code execution or data manipula...

CVE-2021-3110

CRITICAL CVSS 9.8 Jan 20, 2021

CVE-2021-3110 is a time-based blind SQL injection vulnerability in PrestaShop's product comments module. Attackers can exploit this to extract sensitive database information by manipulating the id_pro...

CVE-2020-15160

CRITICAL CVSS 9.8 Sep 24, 2020

CVE-2020-15160 is a blind SQL injection vulnerability in PrestaShop's Catalog Product edition page that allows attackers to execute arbitrary SQL commands. This affects PrestaShop versions 1.7.5.0 thr...

CVE-2024-41651

HIGH CVSS 8.1 Aug 12, 2024

This vulnerability in PrestaShop allows remote code execution through the module upgrade functionality. It affects PrestaShop versions 8.1.7 and earlier. Exploitation requires an attacker to hijack ne...

CVE-2023-30838

HIGH CVSS 8.5 Apr 25, 2023

This vulnerability allows attackers to inject malicious scripts into PrestaShop websites through cross-site scripting (XSS) attacks. The flaw in the ValidateCore::isCleanHTML() method fails to properl...

CVE-2021-43789

HIGH CVSS 7.5 Dec 7, 2021

CVE-2021-43789 is a blind SQL injection vulnerability in PrestaShop e-commerce software that allows attackers to execute arbitrary SQL queries through search filters. This affects PrestaShop versions ...

CVE-2026-25597

MEDIUM CVSS 5.3 Feb 6, 2026

PrestaShop versions before 8.2.4 and 9.0.3 have a time-based user enumeration vulnerability in authentication that allows attackers to determine if customer accounts exist by analyzing response time d...

CVE-2025-25692

MEDIUM CVSS 6.5 Jul 30, 2025

A PHAR deserialization vulnerability in PrestaShop v8.2.0 allows attackers to execute arbitrary code on the server by sending a specially crafted POST request. This affects all websites running Presta...

CVE-2024-36626

MEDIUM CVSS 5.3 Nov 29, 2024

A NULL pointer dereference vulnerability exists in PrestaShop 8.1.4's math_round function in Tools.php. This vulnerability could cause the application to crash when processing certain malformed input....