prestashop/prestashop
PrestaShop is the universal open-source software platform to build your e-commerce solution.
Activity
- Latest release
- Jul 09, 2026
- Total releases
- 119
- Cadence
- ~25 days
- Last 12 months
- 15
Reach
- Stars
- 9.2k
Details
- License
- unknown
- First release
- May 27, 2016
| Version | Released | |
|---|---|---|
9.2.0-beta.1
pre
|
9.2.0-beta.1
pre
Dependencies (162)
+ 154 more
Changelog
Compare changes
|
|
9.1.4
patch
|
9.1.4
patch
Dependencies (161)
+ 153 more
Changelog
Compare changes
|
|
8.2.7
patch
|
8.2.7
patch
Dependencies (117)
+ 109 more
Changelog
Compare changes
|
|
9.1.3
patch
| ||
9.1.2
patch
| ||
9.1.1
patch
|
9.1.1
patch
Dependencies (161)
+ 153 more
Changelog
Compare changes
|
|
8.2.6
patch
| ||
8.2.5
patch
1 CVE
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev | ||
9.1.0
minor
1 CVE
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev | ||
9.1.0-rc.1
pre
3 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev | ||
9.0.3
patch
3 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev |
9.0.3
patch
Dependencies (161)
+ 153 more
Changelog
Compare changes
|
|
8.2.4
patch
3 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev | ||
9.1.0-beta.1
pre
3 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev |
9.1.0-beta.1
pre
Dependencies (161)
+ 153 more
Changelog
Compare changes
|
|
9.0.2
patch
4 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev |
9.0.2
patch
Dependencies (161)
+ 153 more
Changelog
Compare changes
|
|
9.0.1
patch
4 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev |
9.0.1
patch
Dependencies (161)
+ 153 more
Changelog
Compare changes
|
|
8.2.3
patch
4 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev | ||
8.2.2
patch
5 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev |
8.2.2
patch
Dependencies (117)
+ 109 more
Changelog
Compare changes
|
|
9.0.0
major
4 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev |
9.0.0
major
Dependencies (161)
+ 153 more
Changelog
Compare changes
|
|
9.0.0-rc.1
pre
3 CVEs
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev |
9.0.0-rc.1
pre
Dependencies (161)
+ 153 more
Changelog
Compare changes
|
|
8.2.1
patch
5 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev | ||
9.0.0-beta.1
pre
3 CVEs
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev |
9.0.0-beta.1
pre
Dependencies (161)
+ 153 more
Changelog
Compare changes
|
|
8.2.0
minor
5 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev |
8.2.0
minor
Dependencies (117)
+ 109 more
Changelog
Compare changes
|
|
8.1.7
patch
5 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev | ||
9.0.0-alpha.1
pre
3 CVEs
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev |
9.0.0-alpha.1
pre
Dependencies (160)
+ 152 more
Changelog
Compare changes
|
|
8.1.6
patch
5 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev |
8.1.6
patch
Dependencies (117)
+ 109 more
Changelog
Compare changes
|
|
8.1.5
patch
7 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-34717
GHSA-7pjr-2rgh-fc5g
May 14, 2024
Anonymous PrestaShop customer can download other customers' invoices
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactSince PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key parameter in the url. PatchesPatched in 8.1.6 WorkaroundsUpgrade to 8.1.6 Thank you to Samuel Bodevin, who found this vulnerability and shared it with the PrestaShop team. Affected versions
8.1.5
Fixed in
8.1.6
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-34716
GHSA-45vm-3j38-7p78
May 14, 2024
PrestaShop cross-site scripting via customer contact form in FO, through file upload
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
ImpactOnly PrestaShops with customer-thread feature flag enabled are impacted, starting from PrestaShop 8.1.0. The impact is substantial, when the customer thread feature flag is enabled, through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. Consequence: the script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. PatchesThis vulnerability is patched in 8.1.6. WorkaroundsAs long as you have not upgraded to 8.1.6, a simple workaround is to disable the customer-thread feature-flag. Thank you to Ayoub AIT ELMOKHTAR, who discovered this vulnerability and share it with the PrestaShop team. Affected versions
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
Fixed in
8.1.6
References
Updated Jul 16, 2026 · Source: OSV.dev | ||
8.1.4
patch
6 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-34716
GHSA-45vm-3j38-7p78
May 14, 2024
PrestaShop cross-site scripting via customer contact form in FO, through file upload
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
ImpactOnly PrestaShops with customer-thread feature flag enabled are impacted, starting from PrestaShop 8.1.0. The impact is substantial, when the customer thread feature flag is enabled, through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. Consequence: the script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. PatchesThis vulnerability is patched in 8.1.6. WorkaroundsAs long as you have not upgraded to 8.1.6, a simple workaround is to disable the customer-thread feature-flag. Thank you to Ayoub AIT ELMOKHTAR, who discovered this vulnerability and share it with the PrestaShop team. Affected versions
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
Fixed in
8.1.6
References
Updated Jul 16, 2026 · Source: OSV.dev |
8.1.4
patch
Dependencies (117)
+ 109 more
Changelog
Compare changes
|
|
1.7.8.11
patch
14 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-25170
GHSA-3g43-x7qr-96ph
Mar 13, 2023
Possible CSRF token fixation
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
ImpactWhen authenticating users PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enables PatchesThe problem is fixed in version 8.0.1 Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 67 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
8.0.0
8.0.0-beta.1
8.0.0-rc.1
Fixed in
8.0.1
References Updated Jul 16, 2026 · Source: OSV.dev |
1.7.8.11
patch
Dependencies (103)
+ 95 more
Changelog
Compare changes
|
|
8.1.3
patch
7 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-34716
GHSA-45vm-3j38-7p78
May 14, 2024
PrestaShop cross-site scripting via customer contact form in FO, through file upload
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
ImpactOnly PrestaShops with customer-thread feature flag enabled are impacted, starting from PrestaShop 8.1.0. The impact is substantial, when the customer thread feature flag is enabled, through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. Consequence: the script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. PatchesThis vulnerability is patched in 8.1.6. WorkaroundsAs long as you have not upgraded to 8.1.6, a simple workaround is to disable the customer-thread feature-flag. Thank you to Ayoub AIT ELMOKHTAR, who discovered this vulnerability and share it with the PrestaShop team. Affected versions
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
Fixed in
8.1.6
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-26129
GHSA-3366-9287-7qpr
Feb 21, 2024
Path disclosure in JavaScript variable
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactPath disclosure in JavaScript variable PatchesPatch in PrestaShop 8.1.4 Referenceshttps://owasp.org/www-community/attacks/Full_Path_Disclosure Thanks to https://github.com/hugo-fasone Affected versions
8.1.0
8.1.1
8.1.2
8.1.3
Fixed in
8.1.4
References
Updated Jul 16, 2026 · Source: OSV.dev | ||
8.1.2
patch
9 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-34716
GHSA-45vm-3j38-7p78
May 14, 2024
PrestaShop cross-site scripting via customer contact form in FO, through file upload
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
ImpactOnly PrestaShops with customer-thread feature flag enabled are impacted, starting from PrestaShop 8.1.0. The impact is substantial, when the customer thread feature flag is enabled, through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. Consequence: the script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. PatchesThis vulnerability is patched in 8.1.6. WorkaroundsAs long as you have not upgraded to 8.1.6, a simple workaround is to disable the customer-thread feature-flag. Thank you to Ayoub AIT ELMOKHTAR, who discovered this vulnerability and share it with the PrestaShop team. Affected versions
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
Fixed in
8.1.6
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-26129
GHSA-3366-9287-7qpr
Feb 21, 2024
Path disclosure in JavaScript variable
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactPath disclosure in JavaScript variable PatchesPatch in PrestaShop 8.1.4 Referenceshttps://owasp.org/www-community/attacks/Full_Path_Disclosure Thanks to https://github.com/hugo-fasone Affected versions
8.1.0
8.1.1
8.1.2
8.1.3
Fixed in
8.1.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev |
8.1.2
patch
Dependencies (117)
+ 109 more
Changelog
Compare changes
|
|
1.7.8.10
patch
15 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-25170
GHSA-3g43-x7qr-96ph
Mar 13, 2023
Possible CSRF token fixation
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
ImpactWhen authenticating users PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enables PatchesThe problem is fixed in version 8.0.1 Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 67 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
8.0.0
8.0.0-beta.1
8.0.0-rc.1
Fixed in
8.0.1
References Updated Jul 16, 2026 · Source: OSV.dev |
1.7.8.10
patch
Dependencies (103)
+ 95 more
Changelog
Compare changes
|
|
8.1.1
patch
11 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-34716
GHSA-45vm-3j38-7p78
May 14, 2024
PrestaShop cross-site scripting via customer contact form in FO, through file upload
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
ImpactOnly PrestaShops with customer-thread feature flag enabled are impacted, starting from PrestaShop 8.1.0. The impact is substantial, when the customer thread feature flag is enabled, through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. Consequence: the script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. PatchesThis vulnerability is patched in 8.1.6. WorkaroundsAs long as you have not upgraded to 8.1.6, a simple workaround is to disable the customer-thread feature-flag. Thank you to Ayoub AIT ELMOKHTAR, who discovered this vulnerability and share it with the PrestaShop team. Affected versions
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
Fixed in
8.1.6
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-26129
GHSA-3366-9287-7qpr
Feb 21, 2024
Path disclosure in JavaScript variable
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactPath disclosure in JavaScript variable PatchesPatch in PrestaShop 8.1.4 Referenceshttps://owasp.org/www-community/attacks/Full_Path_Disclosure Thanks to https://github.com/hugo-fasone Affected versions
8.1.0
8.1.1
8.1.2
8.1.3
Fixed in
8.1.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev |
8.1.1
patch
Dependencies (117)
+ 109 more
Changelog
Compare changes
|
|
8.0.5
patch
14 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev |
8.0.5
patch
Dependencies (111)
+ 103 more
Changelog
Compare changes
|
|
8.1.0
minor
18 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-34716
GHSA-45vm-3j38-7p78
May 14, 2024
PrestaShop cross-site scripting via customer contact form in FO, through file upload
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
ImpactOnly PrestaShops with customer-thread feature flag enabled are impacted, starting from PrestaShop 8.1.0. The impact is substantial, when the customer thread feature flag is enabled, through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. Consequence: the script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. PatchesThis vulnerability is patched in 8.1.6. WorkaroundsAs long as you have not upgraded to 8.1.6, a simple workaround is to disable the customer-thread feature-flag. Thank you to Ayoub AIT ELMOKHTAR, who discovered this vulnerability and share it with the PrestaShop team. Affected versions
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
Fixed in
8.1.6
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-26129
GHSA-3366-9287-7qpr
Feb 21, 2024
Path disclosure in JavaScript variable
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactPath disclosure in JavaScript variable PatchesPatch in PrestaShop 8.1.4 Referenceshttps://owasp.org/www-community/attacks/Full_Path_Disclosure Thanks to https://github.com/hugo-fasone Affected versions
8.1.0
8.1.1
8.1.2
8.1.3
Fixed in
8.1.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39527
GHSA-xw2r-f8xv-c8xp
Aug 09, 2023
PrestaShop XSS injection through Validate::isCleanHTML method
8.3
/ 10
High
Network
Low
High
Required
Changed
Low
High
High
Impactxss injection through Patches1.7.8.10 8.0.5 8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39526
GHSA-gf46-prm4-56pc
Aug 09, 2023
PrestaShop SQL manager vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactRemote code execution through SQL injection and arbitrary file write in back office Patches1.7.8.10 8.0.5 8.1.1 Found byTruff (via yeswehack) Workaroundsnone Referencesnone Affected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev | ||
8.1.0-rc.1
pre
14 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev |
8.1.0-rc.1
pre
Dependencies (117)
+ 109 more
Changelog
Compare changes
|
|
8.0.4
patch
16 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39527
GHSA-xw2r-f8xv-c8xp
Aug 09, 2023
PrestaShop XSS injection through Validate::isCleanHTML method
8.3
/ 10
High
Network
Low
High
Required
Changed
Low
High
High
Impactxss injection through Patches1.7.8.10 8.0.5 8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39526
GHSA-gf46-prm4-56pc
Aug 09, 2023
PrestaShop SQL manager vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactRemote code execution through SQL injection and arbitrary file write in back office Patches1.7.8.10 8.0.5 8.1.1 Found byTruff (via yeswehack) Workaroundsnone Referencesnone Affected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev | ||
1.7.8.9
patch
17 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39527
GHSA-xw2r-f8xv-c8xp
Aug 09, 2023
PrestaShop XSS injection through Validate::isCleanHTML method
8.3
/ 10
High
Network
Low
High
Required
Changed
Low
High
High
Impactxss injection through Patches1.7.8.10 8.0.5 8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39526
GHSA-gf46-prm4-56pc
Aug 09, 2023
PrestaShop SQL manager vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactRemote code execution through SQL injection and arbitrary file write in back office Patches1.7.8.10 8.0.5 8.1.1 Found byTruff (via yeswehack) Workaroundsnone Referencesnone Affected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-25170
GHSA-3g43-x7qr-96ph
Mar 13, 2023
Possible CSRF token fixation
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
ImpactWhen authenticating users PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enables PatchesThe problem is fixed in version 8.0.1 Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 67 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
8.0.0
8.0.0-beta.1
8.0.0-rc.1
Fixed in
8.0.1
References Updated Jul 16, 2026 · Source: OSV.dev | ||
8.0.3
patch
19 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39527
GHSA-xw2r-f8xv-c8xp
Aug 09, 2023
PrestaShop XSS injection through Validate::isCleanHTML method
8.3
/ 10
High
Network
Low
High
Required
Changed
Low
High
High
Impactxss injection through Patches1.7.8.10 8.0.5 8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39526
GHSA-gf46-prm4-56pc
Aug 09, 2023
PrestaShop SQL manager vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactRemote code execution through SQL injection and arbitrary file write in back office Patches1.7.8.10 8.0.5 8.1.1 Found byTruff (via yeswehack) Workaroundsnone Referencesnone Affected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30545
GHSA-8r4m-5p6p-52rp
Apr 26, 2023
Arbitrary file read via SQL injection
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt is possible for a user having access to the SQL Manager (Advanced Options -> Database) to arbitrary read any file on the Operating system when using SQL function LOAD_FILE in a SELECT request. So It can access to critical information. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30838
GHSA-fh7r-996q-gvcp
Apr 25, 2023
Possible XSS injection through Validate::isCleanHTML method
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
ImpactValidateCore::isCleanHTML() method of Prestashop misses hijickable events which can lead to XSS injection, allowed by the presence of pre-setup @keyframes methods. This XSS which hijacks HTML attributes will be triggered without any interaction of the visitor/administrator which makes it as dangerous as a trivial XSS. Contrary to most XSS which target HTML attributes and which are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 ReferencesAffected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30839
GHSA-p379-cxqh-q822
Apr 25, 2023
SQL filter bypass leading to arbitrary write requests using "SQL Manager"
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactSQL filtering vulnerability, a BO user can write, update and delete in the database, even without having specific rights. PatchesPrestaShop 8.0.4 and 1.7.8.9 will contain the patch. Workaroundsno Referencesno Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev |
8.0.3
patch
Dependencies (111)
+ 103 more
Changelog
Compare changes
|
|
8.0.2
patch
19 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39527
GHSA-xw2r-f8xv-c8xp
Aug 09, 2023
PrestaShop XSS injection through Validate::isCleanHTML method
8.3
/ 10
High
Network
Low
High
Required
Changed
Low
High
High
Impactxss injection through Patches1.7.8.10 8.0.5 8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39526
GHSA-gf46-prm4-56pc
Aug 09, 2023
PrestaShop SQL manager vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactRemote code execution through SQL injection and arbitrary file write in back office Patches1.7.8.10 8.0.5 8.1.1 Found byTruff (via yeswehack) Workaroundsnone Referencesnone Affected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30545
GHSA-8r4m-5p6p-52rp
Apr 26, 2023
Arbitrary file read via SQL injection
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt is possible for a user having access to the SQL Manager (Advanced Options -> Database) to arbitrary read any file on the Operating system when using SQL function LOAD_FILE in a SELECT request. So It can access to critical information. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30838
GHSA-fh7r-996q-gvcp
Apr 25, 2023
Possible XSS injection through Validate::isCleanHTML method
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
ImpactValidateCore::isCleanHTML() method of Prestashop misses hijickable events which can lead to XSS injection, allowed by the presence of pre-setup @keyframes methods. This XSS which hijacks HTML attributes will be triggered without any interaction of the visitor/administrator which makes it as dangerous as a trivial XSS. Contrary to most XSS which target HTML attributes and which are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 ReferencesAffected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30839
GHSA-p379-cxqh-q822
Apr 25, 2023
SQL filter bypass leading to arbitrary write requests using "SQL Manager"
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactSQL filtering vulnerability, a BO user can write, update and delete in the database, even without having specific rights. PatchesPrestaShop 8.0.4 and 1.7.8.9 will contain the patch. Workaroundsno Referencesno Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev | ||
8.1.0-beta.1
pre
14 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev |
8.1.0-beta.1
pre
Dependencies (117)
+ 109 more
Changelog
Compare changes
|
|
8.0.1
patch
19 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39527
GHSA-xw2r-f8xv-c8xp
Aug 09, 2023
PrestaShop XSS injection through Validate::isCleanHTML method
8.3
/ 10
High
Network
Low
High
Required
Changed
Low
High
High
Impactxss injection through Patches1.7.8.10 8.0.5 8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39526
GHSA-gf46-prm4-56pc
Aug 09, 2023
PrestaShop SQL manager vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactRemote code execution through SQL injection and arbitrary file write in back office Patches1.7.8.10 8.0.5 8.1.1 Found byTruff (via yeswehack) Workaroundsnone Referencesnone Affected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30545
GHSA-8r4m-5p6p-52rp
Apr 26, 2023
Arbitrary file read via SQL injection
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt is possible for a user having access to the SQL Manager (Advanced Options -> Database) to arbitrary read any file on the Operating system when using SQL function LOAD_FILE in a SELECT request. So It can access to critical information. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30838
GHSA-fh7r-996q-gvcp
Apr 25, 2023
Possible XSS injection through Validate::isCleanHTML method
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
ImpactValidateCore::isCleanHTML() method of Prestashop misses hijickable events which can lead to XSS injection, allowed by the presence of pre-setup @keyframes methods. This XSS which hijacks HTML attributes will be triggered without any interaction of the visitor/administrator which makes it as dangerous as a trivial XSS. Contrary to most XSS which target HTML attributes and which are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 ReferencesAffected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30839
GHSA-p379-cxqh-q822
Apr 25, 2023
SQL filter bypass leading to arbitrary write requests using "SQL Manager"
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactSQL filtering vulnerability, a BO user can write, update and delete in the database, even without having specific rights. PatchesPrestaShop 8.0.4 and 1.7.8.9 will contain the patch. Workaroundsno Referencesno Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev |
8.0.1
patch
Dependencies (111)
+ 103 more
Changelog
Compare changes
|
|
1.7.8.8
patch
20 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39527
GHSA-xw2r-f8xv-c8xp
Aug 09, 2023
PrestaShop XSS injection through Validate::isCleanHTML method
8.3
/ 10
High
Network
Low
High
Required
Changed
Low
High
High
Impactxss injection through Patches1.7.8.10 8.0.5 8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39526
GHSA-gf46-prm4-56pc
Aug 09, 2023
PrestaShop SQL manager vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactRemote code execution through SQL injection and arbitrary file write in back office Patches1.7.8.10 8.0.5 8.1.1 Found byTruff (via yeswehack) Workaroundsnone Referencesnone Affected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30545
GHSA-8r4m-5p6p-52rp
Apr 26, 2023
Arbitrary file read via SQL injection
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt is possible for a user having access to the SQL Manager (Advanced Options -> Database) to arbitrary read any file on the Operating system when using SQL function LOAD_FILE in a SELECT request. So It can access to critical information. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30838
GHSA-fh7r-996q-gvcp
Apr 25, 2023
Possible XSS injection through Validate::isCleanHTML method
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
ImpactValidateCore::isCleanHTML() method of Prestashop misses hijickable events which can lead to XSS injection, allowed by the presence of pre-setup @keyframes methods. This XSS which hijacks HTML attributes will be triggered without any interaction of the visitor/administrator which makes it as dangerous as a trivial XSS. Contrary to most XSS which target HTML attributes and which are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 ReferencesAffected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30839
GHSA-p379-cxqh-q822
Apr 25, 2023
SQL filter bypass leading to arbitrary write requests using "SQL Manager"
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactSQL filtering vulnerability, a BO user can write, update and delete in the database, even without having specific rights. PatchesPrestaShop 8.0.4 and 1.7.8.9 will contain the patch. Workaroundsno Referencesno Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-25170
GHSA-3g43-x7qr-96ph
Mar 13, 2023
Possible CSRF token fixation
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
ImpactWhen authenticating users PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enables PatchesThe problem is fixed in version 8.0.1 Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 67 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
8.0.0
8.0.0-beta.1
8.0.0-rc.1
Fixed in
8.0.1
References Updated Jul 16, 2026 · Source: OSV.dev | ||
8.0.0
major
20 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39527
GHSA-xw2r-f8xv-c8xp
Aug 09, 2023
PrestaShop XSS injection through Validate::isCleanHTML method
8.3
/ 10
High
Network
Low
High
Required
Changed
Low
High
High
Impactxss injection through Patches1.7.8.10 8.0.5 8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39526
GHSA-gf46-prm4-56pc
Aug 09, 2023
PrestaShop SQL manager vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactRemote code execution through SQL injection and arbitrary file write in back office Patches1.7.8.10 8.0.5 8.1.1 Found byTruff (via yeswehack) Workaroundsnone Referencesnone Affected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30545
GHSA-8r4m-5p6p-52rp
Apr 26, 2023
Arbitrary file read via SQL injection
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt is possible for a user having access to the SQL Manager (Advanced Options -> Database) to arbitrary read any file on the Operating system when using SQL function LOAD_FILE in a SELECT request. So It can access to critical information. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30838
GHSA-fh7r-996q-gvcp
Apr 25, 2023
Possible XSS injection through Validate::isCleanHTML method
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
ImpactValidateCore::isCleanHTML() method of Prestashop misses hijickable events which can lead to XSS injection, allowed by the presence of pre-setup @keyframes methods. This XSS which hijacks HTML attributes will be triggered without any interaction of the visitor/administrator which makes it as dangerous as a trivial XSS. Contrary to most XSS which target HTML attributes and which are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 ReferencesAffected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30839
GHSA-p379-cxqh-q822
Apr 25, 2023
SQL filter bypass leading to arbitrary write requests using "SQL Manager"
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactSQL filtering vulnerability, a BO user can write, update and delete in the database, even without having specific rights. PatchesPrestaShop 8.0.4 and 1.7.8.9 will contain the patch. Workaroundsno Referencesno Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-25170
GHSA-3g43-x7qr-96ph
Mar 13, 2023
Possible CSRF token fixation
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
ImpactWhen authenticating users PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enables PatchesThe problem is fixed in version 8.0.1 Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 67 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
8.0.0
8.0.0-beta.1
8.0.0-rc.1
Fixed in
8.0.1
References Updated Jul 16, 2026 · Source: OSV.dev | ||
8.0.0-rc.1
pre
15 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-25170
GHSA-3g43-x7qr-96ph
Mar 13, 2023
Possible CSRF token fixation
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
ImpactWhen authenticating users PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enables PatchesThe problem is fixed in version 8.0.1 Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 67 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
8.0.0
8.0.0-beta.1
8.0.0-rc.1
Fixed in
8.0.1
References Updated Jul 16, 2026 · Source: OSV.dev | ||
8.0.0-beta.1
pre
15 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-25170
GHSA-3g43-x7qr-96ph
Mar 13, 2023
Possible CSRF token fixation
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
ImpactWhen authenticating users PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enables PatchesThe problem is fixed in version 8.0.1 Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 67 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
8.0.0
8.0.0-beta.1
8.0.0-rc.1
Fixed in
8.0.1
References Updated Jul 16, 2026 · Source: OSV.dev |
8.0.0-beta.1
pre
Dependencies (111)
+ 103 more
Changelog
Compare changes
|
|
1.7.8.7
patch
21 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39527
GHSA-xw2r-f8xv-c8xp
Aug 09, 2023
PrestaShop XSS injection through Validate::isCleanHTML method
8.3
/ 10
High
Network
Low
High
Required
Changed
Low
High
High
Impactxss injection through Patches1.7.8.10 8.0.5 8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39526
GHSA-gf46-prm4-56pc
Aug 09, 2023
PrestaShop SQL manager vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactRemote code execution through SQL injection and arbitrary file write in back office Patches1.7.8.10 8.0.5 8.1.1 Found byTruff (via yeswehack) Workaroundsnone Referencesnone Affected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30545
GHSA-8r4m-5p6p-52rp
Apr 26, 2023
Arbitrary file read via SQL injection
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt is possible for a user having access to the SQL Manager (Advanced Options -> Database) to arbitrary read any file on the Operating system when using SQL function LOAD_FILE in a SELECT request. So It can access to critical information. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30838
GHSA-fh7r-996q-gvcp
Apr 25, 2023
Possible XSS injection through Validate::isCleanHTML method
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
ImpactValidateCore::isCleanHTML() method of Prestashop misses hijickable events which can lead to XSS injection, allowed by the presence of pre-setup @keyframes methods. This XSS which hijacks HTML attributes will be triggered without any interaction of the visitor/administrator which makes it as dangerous as a trivial XSS. Contrary to most XSS which target HTML attributes and which are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 ReferencesAffected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30839
GHSA-p379-cxqh-q822
Apr 25, 2023
SQL filter bypass leading to arbitrary write requests using "SQL Manager"
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactSQL filtering vulnerability, a BO user can write, update and delete in the database, even without having specific rights. PatchesPrestaShop 8.0.4 and 1.7.8.9 will contain the patch. Workaroundsno Referencesno Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-25170
GHSA-3g43-x7qr-96ph
Mar 13, 2023
Possible CSRF token fixation
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
ImpactWhen authenticating users PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enables PatchesThe problem is fixed in version 8.0.1 Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 67 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
8.0.0
8.0.0-beta.1
8.0.0-rc.1
Fixed in
8.0.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2022-46158
GHSA-9qgp-9wwc-v29r
Dec 08, 2022
PrestaShop has potential Information exposure in the upload directory
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactPotential Information exposure in the upload directory. PatchesPatch in PrestaShop 1.7.8.8 Referenceshttps://capec.mitre.org/data/definitions/87.html Thanks to DZPATROL Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 63 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
Fixed in
1.7.8.8
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.7.8.7
patch
Dependencies (103)
+ 95 more
Changelog
Compare changes
|
|
1.7.8.6
patch
22 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39527
GHSA-xw2r-f8xv-c8xp
Aug 09, 2023
PrestaShop XSS injection through Validate::isCleanHTML method
8.3
/ 10
High
Network
Low
High
Required
Changed
Low
High
High
Impactxss injection through Patches1.7.8.10 8.0.5 8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39526
GHSA-gf46-prm4-56pc
Aug 09, 2023
PrestaShop SQL manager vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactRemote code execution through SQL injection and arbitrary file write in back office Patches1.7.8.10 8.0.5 8.1.1 Found byTruff (via yeswehack) Workaroundsnone Referencesnone Affected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30545
GHSA-8r4m-5p6p-52rp
Apr 26, 2023
Arbitrary file read via SQL injection
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt is possible for a user having access to the SQL Manager (Advanced Options -> Database) to arbitrary read any file on the Operating system when using SQL function LOAD_FILE in a SELECT request. So It can access to critical information. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30838
GHSA-fh7r-996q-gvcp
Apr 25, 2023
Possible XSS injection through Validate::isCleanHTML method
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
ImpactValidateCore::isCleanHTML() method of Prestashop misses hijickable events which can lead to XSS injection, allowed by the presence of pre-setup @keyframes methods. This XSS which hijacks HTML attributes will be triggered without any interaction of the visitor/administrator which makes it as dangerous as a trivial XSS. Contrary to most XSS which target HTML attributes and which are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 ReferencesAffected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30839
GHSA-p379-cxqh-q822
Apr 25, 2023
SQL filter bypass leading to arbitrary write requests using "SQL Manager"
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactSQL filtering vulnerability, a BO user can write, update and delete in the database, even without having specific rights. PatchesPrestaShop 8.0.4 and 1.7.8.9 will contain the patch. Workaroundsno Referencesno Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-25170
GHSA-3g43-x7qr-96ph
Mar 13, 2023
Possible CSRF token fixation
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
ImpactWhen authenticating users PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enables PatchesThe problem is fixed in version 8.0.1 Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 67 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
8.0.0
8.0.0-beta.1
8.0.0-rc.1
Fixed in
8.0.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2022-46158
GHSA-9qgp-9wwc-v29r
Dec 08, 2022
PrestaShop has potential Information exposure in the upload directory
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactPotential Information exposure in the upload directory. PatchesPatch in PrestaShop 1.7.8.8 Referenceshttps://capec.mitre.org/data/definitions/87.html Thanks to DZPATROL Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 63 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
Fixed in
1.7.8.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-31181
GHSA-hrgx-p36p-89q4
Jul 29, 2022
PrestaShop eval injection possible if shop vulnerable to SQL injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactEval injection possible if the shop is vulnerable to an SQL injection. PatchesThe problem is fixed in version 1.7.8.7 WorkaroundsDelete the MySQL Smarty cache feature by removing these lines in the file
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 62 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
Fixed in
1.7.8.7
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
1.7.8.5
patch
22 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39527
GHSA-xw2r-f8xv-c8xp
Aug 09, 2023
PrestaShop XSS injection through Validate::isCleanHTML method
8.3
/ 10
High
Network
Low
High
Required
Changed
Low
High
High
Impactxss injection through Patches1.7.8.10 8.0.5 8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39526
GHSA-gf46-prm4-56pc
Aug 09, 2023
PrestaShop SQL manager vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactRemote code execution through SQL injection and arbitrary file write in back office Patches1.7.8.10 8.0.5 8.1.1 Found byTruff (via yeswehack) Workaroundsnone Referencesnone Affected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30545
GHSA-8r4m-5p6p-52rp
Apr 26, 2023
Arbitrary file read via SQL injection
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt is possible for a user having access to the SQL Manager (Advanced Options -> Database) to arbitrary read any file on the Operating system when using SQL function LOAD_FILE in a SELECT request. So It can access to critical information. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30838
GHSA-fh7r-996q-gvcp
Apr 25, 2023
Possible XSS injection through Validate::isCleanHTML method
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
ImpactValidateCore::isCleanHTML() method of Prestashop misses hijickable events which can lead to XSS injection, allowed by the presence of pre-setup @keyframes methods. This XSS which hijacks HTML attributes will be triggered without any interaction of the visitor/administrator which makes it as dangerous as a trivial XSS. Contrary to most XSS which target HTML attributes and which are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 ReferencesAffected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30839
GHSA-p379-cxqh-q822
Apr 25, 2023
SQL filter bypass leading to arbitrary write requests using "SQL Manager"
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactSQL filtering vulnerability, a BO user can write, update and delete in the database, even without having specific rights. PatchesPrestaShop 8.0.4 and 1.7.8.9 will contain the patch. Workaroundsno Referencesno Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-25170
GHSA-3g43-x7qr-96ph
Mar 13, 2023
Possible CSRF token fixation
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
ImpactWhen authenticating users PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enables PatchesThe problem is fixed in version 8.0.1 Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 67 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
8.0.0
8.0.0-beta.1
8.0.0-rc.1
Fixed in
8.0.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2022-46158
GHSA-9qgp-9wwc-v29r
Dec 08, 2022
PrestaShop has potential Information exposure in the upload directory
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactPotential Information exposure in the upload directory. PatchesPatch in PrestaShop 1.7.8.8 Referenceshttps://capec.mitre.org/data/definitions/87.html Thanks to DZPATROL Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 63 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
Fixed in
1.7.8.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-31181
GHSA-hrgx-p36p-89q4
Jul 29, 2022
PrestaShop eval injection possible if shop vulnerable to SQL injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactEval injection possible if the shop is vulnerable to an SQL injection. PatchesThe problem is fixed in version 1.7.8.7 WorkaroundsDelete the MySQL Smarty cache feature by removing these lines in the file
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 62 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
Fixed in
1.7.8.7
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
1.7.8.4
patch
22 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39527
GHSA-xw2r-f8xv-c8xp
Aug 09, 2023
PrestaShop XSS injection through Validate::isCleanHTML method
8.3
/ 10
High
Network
Low
High
Required
Changed
Low
High
High
Impactxss injection through Patches1.7.8.10 8.0.5 8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39526
GHSA-gf46-prm4-56pc
Aug 09, 2023
PrestaShop SQL manager vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactRemote code execution through SQL injection and arbitrary file write in back office Patches1.7.8.10 8.0.5 8.1.1 Found byTruff (via yeswehack) Workaroundsnone Referencesnone Affected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30545
GHSA-8r4m-5p6p-52rp
Apr 26, 2023
Arbitrary file read via SQL injection
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt is possible for a user having access to the SQL Manager (Advanced Options -> Database) to arbitrary read any file on the Operating system when using SQL function LOAD_FILE in a SELECT request. So It can access to critical information. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30838
GHSA-fh7r-996q-gvcp
Apr 25, 2023
Possible XSS injection through Validate::isCleanHTML method
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
ImpactValidateCore::isCleanHTML() method of Prestashop misses hijickable events which can lead to XSS injection, allowed by the presence of pre-setup @keyframes methods. This XSS which hijacks HTML attributes will be triggered without any interaction of the visitor/administrator which makes it as dangerous as a trivial XSS. Contrary to most XSS which target HTML attributes and which are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 ReferencesAffected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30839
GHSA-p379-cxqh-q822
Apr 25, 2023
SQL filter bypass leading to arbitrary write requests using "SQL Manager"
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactSQL filtering vulnerability, a BO user can write, update and delete in the database, even without having specific rights. PatchesPrestaShop 8.0.4 and 1.7.8.9 will contain the patch. Workaroundsno Referencesno Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-25170
GHSA-3g43-x7qr-96ph
Mar 13, 2023
Possible CSRF token fixation
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
ImpactWhen authenticating users PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enables PatchesThe problem is fixed in version 8.0.1 Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 67 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
8.0.0
8.0.0-beta.1
8.0.0-rc.1
Fixed in
8.0.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2022-46158
GHSA-9qgp-9wwc-v29r
Dec 08, 2022
PrestaShop has potential Information exposure in the upload directory
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactPotential Information exposure in the upload directory. PatchesPatch in PrestaShop 1.7.8.8 Referenceshttps://capec.mitre.org/data/definitions/87.html Thanks to DZPATROL Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 63 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
Fixed in
1.7.8.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-31181
GHSA-hrgx-p36p-89q4
Jul 29, 2022
PrestaShop eval injection possible if shop vulnerable to SQL injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactEval injection possible if the shop is vulnerable to an SQL injection. PatchesThe problem is fixed in version 1.7.8.7 WorkaroundsDelete the MySQL Smarty cache feature by removing these lines in the file
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 62 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
Fixed in
1.7.8.7
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
1.7.8.3
patch
22 CVEs
CVE-2026-44212
GHSA-w9f3-qc75-qgx9
May 08, 2026
PrestaShop has a stored XSS executable in customer service view
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactThis is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. PatchesPatched in PrestaShop 8.2.6 and 9.1.1. WorkaroundsNone. Resources
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 98 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.6
9.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33673
GHSA-35pf-37c6-jxjv
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. PatchesPatched on 8.2.5 and 9.1.0 WorkaroundsNone ReferencesNone Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
+ 99 more Show less
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-33674
GHSA-283w-xf3q-788v
Mar 25, 2026
PrestaShop: Improper Use of Validation Framework
2.0
/ 10
Low
Network
High
High
Required
Unchanged
None
Low
None
ImpactFix improper use of validation framework PatchesPatched in 8.2.5 and 9.1.0 WorkaroundsNone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 99 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
8.2.4
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
9.0.3
9.1.0-beta.1
9.1.0-rc.1
Fixed in
8.2.5
9.1.0
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2026-25597
GHSA-67v7-3g49-mxh2
Feb 03, 2026
PrestaShop affected by time based enumeration in FO login form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactA time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches8.2.4 and 9.0.3 Workaroundsnone ReferencesFound by Lam Yiu Tung Affected versions
9.0.0
9.0.0-alpha.1
9.0.0-beta.1
9.0.0-rc.1
9.0.1
9.0.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 95 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
8.2.3
Fixed in
8.2.4
9.0.3
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2025-51586
GHSA-8xx5-h6m3-jr33
Sep 04, 2025
Presta Shop vulnerable to email enumeration
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
ImpactAn unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses. Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts. PatchesPrestaShop 8.2.3 WorkaroundsYou must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/ Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 88 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.2.0
8.2.1
8.2.2
Fixed in
8.2.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21628
GHSA-vr7m-r9vm-m4wf
Jan 03, 2024
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
None
Low
ImpactThe isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent. Be careful if you have a module fetching these messages from the DB and displaying it without escaping html. Patches8.1.x ReporterReported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/) Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 80 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
8.1.2
Fixed in
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2024-21627
GHSA-xgpm-q3mq-46rq
Jan 03, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
8.1
/ 10
High
Network
Low
High
Required
Changed
High
High
None
DescriptionSome event attributes are not detected by the isCleanHTML method ImpactSome modules using the isCleanHTML method could be vulnerable to xss Patches8.1.3, 1.7.8.11 WorkaroundsThe best workaround is to use the ReportersReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub). Affected versions
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
+ 79 more Show less
8.1.2
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.11
8.1.3
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43663
GHSA-6jmf-2pfc-q9m7
Sep 28, 2023
PrestaShop allows users to uninstall modules from backoffice, even with low rights
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAny module can be disabled or uninstalled from back office, even with low user right. Patches8.1.2 Workaroundsnone ReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-43664
GHSA-gvrg-62jp-rf7j
Sep 28, 2023
PrestaShop allows employee without any access rights to list all installed modules
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactIn BO, an employee can list all modules without any access rights: method PatchesFixed on 8.1.2 WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 79 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
8.1.1
Fixed in
8.1.2
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39530
GHSA-v4gr-v679-42p7
Aug 09, 2023
PrestaShop file deletion via CustomerMessage
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIt is possible to delete files from the server via the CustomerMessage API Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39529
GHSA-2rf5-3fw8-qm47
Aug 09, 2023
PrestaShop file deletion via attachment API
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactIt is possible to delete a file from the server by using the Attachments controller and the Attachments API. Patches8.1.1 Found byKto94 (via Yeswehack) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39528
GHSA-hpf4-v7v2-95p2
Aug 09, 2023
PrestaShop file access through path traversal
6.8
/ 10
Medium
Network
Low
High
None
Changed
None
High
None
Impact
This vulnerability can be exacerbated when coupled with CWE-502, which pertains to the Deserialization of Untrusted Data. Such a combination could potentially lead to a Remote Code Execution (RCE) vulnerability Patches8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39527
GHSA-xw2r-f8xv-c8xp
Aug 09, 2023
PrestaShop XSS injection through Validate::isCleanHTML method
8.3
/ 10
High
Network
Low
High
Required
Changed
Low
High
High
Impactxss injection through Patches1.7.8.10 8.0.5 8.1.1 Found byAleksey Solovev (Positive Technologies) WorkaroundsReferencesAffected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39526
GHSA-gf46-prm4-56pc
Aug 09, 2023
PrestaShop SQL manager vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactRemote code execution through SQL injection and arbitrary file write in back office Patches1.7.8.10 8.0.5 8.1.1 Found byTruff (via yeswehack) Workaroundsnone Referencesnone Affected versions
8.1.0
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
+ 71 more Show less
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
Fixed in
1.7.8.10
8.0.5
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39525
GHSA-m9r4-3fg7-pqm2
Aug 09, 2023
PrestaShop path traversal
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIn the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path. Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-39524
GHSA-75p5-jwx4-qw9h
Aug 09, 2023
PrestaShop boolean SQL injection
6.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
High
ImpactSQL injection possible in product search field, in BO's product page Patches8.1.1 Found byAleksey Solovev (Positive Technologies) Workaroundsnone Referencesnone Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 78 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.10
1.7.8.11
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
1.7.8.9
8.0.0
8.0.0-beta.1
8.0.0-rc.1
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.0-beta.1
8.1.0-rc.1
Fixed in
8.1.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30545
GHSA-8r4m-5p6p-52rp
Apr 26, 2023
Arbitrary file read via SQL injection
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt is possible for a user having access to the SQL Manager (Advanced Options -> Database) to arbitrary read any file on the Operating system when using SQL function LOAD_FILE in a SELECT request. So It can access to critical information. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30838
GHSA-fh7r-996q-gvcp
Apr 25, 2023
Possible XSS injection through Validate::isCleanHTML method
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
ImpactValidateCore::isCleanHTML() method of Prestashop misses hijickable events which can lead to XSS injection, allowed by the presence of pre-setup @keyframes methods. This XSS which hijacks HTML attributes will be triggered without any interaction of the visitor/administrator which makes it as dangerous as a trivial XSS. Contrary to most XSS which target HTML attributes and which are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. PatchesThe patch will be on PS 8.0.4 and PS 1.7.8.9 ReferencesAffected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-30839
GHSA-p379-cxqh-q822
Apr 25, 2023
SQL filter bypass leading to arbitrary write requests using "SQL Manager"
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactSQL filtering vulnerability, a BO user can write, update and delete in the database, even without having specific rights. PatchesPrestaShop 8.0.4 and 1.7.8.9 will contain the patch. Workaroundsno Referencesno Affected versions
8.0.0
8.0.1
8.0.2
8.0.3
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
+ 68 more Show less
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
Fixed in
1.7.8.9
8.0.4
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2023-25170
GHSA-3g43-x7qr-96ph
Mar 13, 2023
Possible CSRF token fixation
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
ImpactWhen authenticating users PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enables PatchesThe problem is fixed in version 8.0.1 Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 67 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
1.7.8.8
8.0.0
8.0.0-beta.1
8.0.0-rc.1
Fixed in
8.0.1
References Updated Jul 16, 2026 · Source: OSV.dev
CVE-2022-46158
GHSA-9qgp-9wwc-v29r
Dec 08, 2022
PrestaShop has potential Information exposure in the upload directory
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactPotential Information exposure in the upload directory. PatchesPatch in PrestaShop 1.7.8.8 Referenceshttps://capec.mitre.org/data/definitions/87.html Thanks to DZPATROL Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 63 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
1.7.8.7
Fixed in
1.7.8.8
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-31181
GHSA-hrgx-p36p-89q4
Jul 29, 2022
PrestaShop eval injection possible if shop vulnerable to SQL injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactEval injection possible if the shop is vulnerable to an SQL injection. PatchesThe problem is fixed in version 1.7.8.7 WorkaroundsDelete the MySQL Smarty cache feature by removing these lines in the file
Affected versions
1.7.0.0
1.7.0.0-beta.1.0
1.7.0.0-beta.2.0
1.7.0.0-beta.3.0
1.7.0.0-beta.4.0
1.7.0.0-rc.0.0
1.7.0.0-rc.1.0
1.7.0.0-rc.2.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.0.4
+ 62 more Show less
1.7.0.5
1.7.0.6
1.7.1.0
1.7.1.1
1.7.1.2
1.7.2.0
1.7.2.0-rc.1.0
1.7.2.1
1.7.2.2
1.7.2.3
1.7.2.4
1.7.2.5
1.7.3.0
1.7.3.1
1.7.3.2
1.7.3.3
1.7.3.4
1.7.4.0
1.7.4.0-beta.1
1.7.4.1
1.7.4.2
1.7.4.3
1.7.4.4
1.7.5.0
1.7.5.0-beta.1
1.7.5.0-rc.1
1.7.5.1
1.7.5.2
1.7.6.0
1.7.6.0-beta.1
1.7.6.0-rc.1
1.7.6.0-rc.2
1.7.6.1
1.7.6.2
1.7.6.3
1.7.6.4
1.7.6.5
1.7.6.6
1.7.6.7
1.7.6.8
1.7.6.9
1.7.7.0
1.7.7.0-beta.1
1.7.7.0-beta.2
1.7.7.0-rc.1
1.7.7.1
1.7.7.2
1.7.7.3
1.7.7.4
1.7.7.5
1.7.7.6
1.7.7.7
1.7.7.8
1.7.8.0
1.7.8.0-beta.1
1.7.8.0-rc.1
1.7.8.1
1.7.8.2
1.7.8.3
1.7.8.4
1.7.8.5
1.7.8.6
Fixed in
1.7.8.7
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.7.8.3
patch
Dependencies (103)
+ 95 more
Changelog
Compare changes
|