← Back

Productcomments

productcomments

Vendor: Prestashop • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Prestashop
1Productcomments
Jun 17, 2026
Sep 2, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an administrator's cookie. The issue is fixed in version 5.0.2.
1Prestashop
1Productcomments
Jun 17, 2026
Dec 3, 2020
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.