← Back

Prestashop

prestashop

127 CVEs • 31 products

Products (31)

Click to collapse
Toggle
Prestashop
prestashop
Eo Tags
eo_tags
M4 Pdf
m4_pdf
Ebay Module
ebay_module
Ebay
ebay
Contactform
contactform
Blockwishlist
blockwishlist
Xen Forum
xen_forum
Dpd France
dpd_france
Payplug
payplug
Amazon
amazon
Pk Customlinks
pk_customlinks

CVEs (127)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Prestashop
1Prestashop
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In PrestaShop between versions 1.7.4.0 and 1.7.6.5, there is a reflected XSS when uploading a wrong file. The problem is fixed in 1.7.6.5
1Prestashop
1Prestashop
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is a reflected XSS with `back` parameter. The problem is fixed in 1.7.6.5
1Prestashop
1Prestashop
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-dev/index.php/configure/shop/customer-preferences/ - admin-dev/index.php...Show more
In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-dev/index.php/configure/shop/customer-preferences/ - admin-dev/index.php/improve/international/translations/ - admin-dev/index.php/improve/international/geolocation/ - admin-dev/index.php/improve/international/localization - admin-dev/index.php/configure/advanced/performance - admin-dev/index.php/sell/orders/delivery-slips/ - admin-dev/index.php?controller=AdminStatuses The problem is fixed in 1.7.6.5Show less
1Prestashop
1Prestashop
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In PrestaShop between versions 1.5.4.0 and 1.7.6.5, there is a reflected XSS on Exception page The problem is fixed in 1.7.6.5
1Prestashop
1Prestashop
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In PrestaShop between versions 1.7.1.0 and 1.7.6.5, there is a reflected XSS on AdminCarts page with `cartBox` parameter The problem is fixed in 1.7.6.5
1Prestashop
1Prestashop
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is a reflected XSS on Search page with `alias` and `search` parameters. The problem is patched in 1.7.6.5
1Prestashop
1Prestashop
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters in the dashboard page This problem is fixed in 1.7.6.5
1Prestashop
1Prestashop
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts can be many, and vary from the theft of information and credentials to the redirection to malicious...Show more
In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts can be many, and vary from the theft of information and credentials to the redirection to malicious websites containing attacker-controlled content, which in some cases even cause XSS attacks. So even though an open redirection might sound harmless at first, the impacts of it can be severe should it be exploitable. The problem is fixed in 1.7.6.5Show less
1Prestashop
1Prestashop
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5
1Prestashop
1Prestashop
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminAttributesGroups page. The problem is patched in 1.7.6.5.
1Prestashop
1Prestashop
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In PrestaShop before version 1.7.6.5, there is a reflected XSS while running the security compromised page. It allows anyone to execute arbitrary action. The problem is patched in the 1.7.6.5.
1Prestashop
1Prestashop Socialfollow
Jun 17, 2026
Apr 16, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflected XSS with social networks fields The problem is fixed in 2.1.0
1Prestashop
1Prestashop Linklist
Jun 17, 2026
Apr 16, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In PrestaShop module ps_linklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fixed in version 3.1.0
1Prestashop
1Prestashop Link
Jun 17, 2026
Apr 16, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In the ps_link module for PrestaShop before version 3.1.0, there is a stored XSS when you create or edit a link list block with the title field. The problem is fixed in 3.1.0
1Prestashop
1Faceted Search Module
Jun 17, 2026
Mar 25, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with `url_name` parameter. The problem is fixed in 3.5.0
1Prestashop
1Prestashop
Jun 17, 2026
Mar 5, 2020
N/A· v4
6.3 MEDIUM· v3
4.9 MEDIUM· v2
In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address. It is the same with CustomerForm, you are able to chang...Show more
In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address. It is the same with CustomerForm, you are able to change the id_customer and change all information of all accounts. The problem is patched in version 1.7.6.4.Show less
1Prestashop
1Prestashop
Nov 21, 2024
Feb 18, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module
1Prestashop
1Prestashop
Nov 21, 2024
Feb 14, 2020
N/A· v4
5.5 MEDIUM· v3
3.5 LOW· v2
PrestaShop before 1.4.11 allows logout CSRF.
1Prestashop
1Prestashop
Nov 21, 2024
Feb 14, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.
1Prestashop
1Prestashop
Nov 21, 2024
Feb 11, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.