Exposure of PrestaShop

CMS, Ecommerce
80
exposure score
51,019
sites use
0
exploited
8
critical
Vexday analysis

Com 61 CVEs catalogadas e nenhuma confirmada em exploração ativa no catálogo CISA KEV, o PrestaShop apresenta taxa de exploração abaixo da média geral, o que não elimina riscos relevantes. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que tende a ser subestimado, mas que em plataformas de e-commerce expõe dados de clientes e sessões administrativas a ataques de injeção de conteúdo. A CVE mais preocupante no momento é CVE-2024-34716, com score EPSS de 0,5617 — valor que indica probabilidade considerável de exploração em ambiente real e justifica priorização imediata de correção. As 8 vulnerabilidades de severidade crítica no histórico reforçam a necessidade de manter ciclos curtos de atualização, especialmente em instalações com módulos de terceiros.

CVEs

61 results
CVE-2024-34716CRITICALPrestaShop vulnerable to XSS via customer contact form in FO, through file uploadEPSS 56.2%CVE-2020-15160Blind SQL Injection in PrestaShopEPSS 10.8%CVE-2022-31181CRITICALRemote code execution in prestashopEPSS 6.5%CVE-2021-43789HIGHBlind SQLi using Search filters in PrestaShopEPSS 4.6%CVE-2022-21686CRITICALServer Side Twig Template Injection in PrestaShopEPSS 1.8%CVE-2020-4074HIGHImproper AuthenticationEPSS 1.8%CVE-2020-26224HIGHImproper Access Control in PrestaShopEPSS 1.7%CVE-2023-30839CRITICALPrestaShop vulnerable to SQL filter bypass leading to arbitrary write requests using "SQL Manager"EPSS 1.7%CVE-2020-15081MEDIUMInformation exposure in the upload directory in PrestaShopEPSS 1.6%CVE-2021-21302MEDIUMCSV Injection via csv exportEPSS 1.4%CVE-2023-39526CRITICALPrestaShopSQL manager vulnerability (potential RCE)EPSS 1.3%CVE-2020-15082HIGHExternal control of configuration setting in the dashboard in PrestaShopEPSS 1.2%CVE-2021-21308MEDIUMImproper session management for soft logoutEPSS 1.0%CVE-2023-30838HIGHPrestaShop vulnerable to possible XSS injection through Validate::isCleanHTML methodEPSS 1.0%CVE-2020-15080MEDIUMInformation disclosure in release archive in PrestaShopEPSS 0.9%CVE-2020-15161MEDIUMPotential XSS in PrestaShopEPSS 0.9%CVE-2023-30545HIGHPrestaShop arbitrary file read vulnerabilityEPSS 0.9%CVE-2020-5250HIGHPossible information disclosure in PrestaShopEPSS 0.9%CVE-2020-5272MEDIUMReflected XSS on Search page of PrestaShopEPSS 0.8%CVE-2020-5270MEDIUMOpen redirection when using back parameter of PrestaShopEPSS 0.8%