Vulnerabilities in Prestashop

74 results
Vexday analysis

PrestaShop apresenta 3 vulnerabilidades registradas na base do Vexday, todas relacionadas a injeção de código (CWE-79), mas nenhuma está sob exploração ativa confirmada e todas têm histórico anterior a 90 dias. O risco operacional é baixo no contexto atual, embora a persistência de falhas de validação de entrada permaneça como vetor de preocupação para implementações desatualizadas.

CVE-2022-45447MEDIUMPath Traversal in M4 PDF plugin for Prestashop sitesEPSS 0.7%CVE-2021-21398MEDIUMPossible XSS injection through DataColumn Grid classEPSS 0.7%CVE-2020-5277MEDIUMReflected XSS with url_name parameter of PrestaShop module ps_facetedsearchEPSS 0.7%CVE-2020-5273MEDIUMStored XSS with custom URLs in PrestaShop module ps_linklistEPSS 0.7%CVE-2020-5294MEDIUMReflected XSS with social networks fieldsEPSS 0.7%CVE-2020-5293MEDIUMImproper access control on product page with combinations, attachments and specific prices in PrestaShopEPSS 0.7%CVE-2020-5287MEDIUMImproper access control on customers search in PrestaShopEPSS 0.7%CVE-2020-5288MEDIUMImproper access control on product attributes page in PrestaShopEPSS 0.7%CVE-2020-5286MEDIUMReflected XSS related in import page in PrestaShopEPSS 0.7%CVE-2023-39524MEDIUMPrestaShop vulnerable to boolean SQL injection in search product in BOEPSS 0.7%CVE-2020-15083MEDIUMReflected XSS when uploading an image in the Product page in PrestaShopEPSS 0.7%CVE-2020-5266MEDIUMStored XSS on back office edit pageEPSS 0.6%CVE-2024-26129MEDIUMPrestashop vulnerable to path disclosure in JavaScript variableEPSS 0.6%CVE-2020-11074MEDIUMStored XSS in PrestaShopEPSS 0.6%CVE-2020-15079MEDIUMImproper access control in PrestaShopEPSS 0.6%CVE-2024-34717MEDIUMAnonymous PrestaShop customer can download other customers' invoicesEPSS 0.5%CVE-2024-21627HIGHSome attribute not escaped in Validate::isCleanHTML methodEPSS 0.5%CVE-2023-39527HIGHPrestaShop XSS vulnerability through Validate::isCleanHTML methodEPSS 0.5%CVE-2022-35933MEDIUMPrestaShop module Product Comments vulnerable to cross-site scripting (XSS)EPSS 0.5%CVE-2022-46158MEDIUMPotential Information exposure in the upload directory in PrestaShopEPSS 0.5%