Vulnerabilities
Vulnerable Software
Prestashop:  Security Vulnerabilities
prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.
CVSS Score
8.1
EPSS Score
0.451
Published
2022-06-27
PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds.
CVSS Score
9.0
EPSS Score
0.006
Published
2022-01-26
PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.
CVSS Score
6.1
EPSS Score
0.004
Published
2021-12-21
PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search filters with `orderBy` and `sortOrder` parameters. The problem is fixed in version 1.7.8.2.
CVSS Score
7.5
EPSS Score
0.13
Published
2021-12-07
ps_emailsubscription is a newsletter subscription module for the PrestaShop platform. An employee can inject javascript in the newsletter condition field that will then be executed on the front office The issue has been fixed in 2.6.1
CVSS Score
4.6
EPSS Score
0.003
Published
2021-03-31
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can inject HTML when the Grid Column Type DataColumn is badly used. The problem is fixed in 1.7.7.3
CVSS Score
5.4
EPSS Score
0.003
Published
2021-03-30
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2
CVSS Score
6.8
EPSS Score
0.005
Published
2021-02-26
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an attacker is able to foreign request and executes customer commands. The problem is fixed in 1.7.7.2
CVSS Score
6.1
EPSS Score
0.004
Published
2021-02-26
The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.
CVSS Score
9.8
EPSS Score
0.793
Published
2021-01-20
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.
CVSS Score
6.8
EPSS Score
0.81
Published
2020-12-03


Contact Us

Shodan ® - All rights reserved