Vulnerabilities > Prestashop

DATE CVE VULNERABILITY TITLE RISK
2024-01-16 CVE-2023-48926 Missing Authorization vulnerability in Prestashop Advanced Loyalty Program
An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.
network
low complexity
prestashop CWE-862
5.3
2024-01-02 CVE-2024-21628 Cross-site Scripting vulnerability in Prestashop
PrestaShop is an open-source e-commerce platform.
network
low complexity
prestashop CWE-79
6.1
2024-01-02 CVE-2024-21627 Cross-site Scripting vulnerability in Prestashop
PrestaShop is an open-source e-commerce platform.
network
low complexity
prestashop CWE-79
6.1
2023-11-09 CVE-2023-47110 Unspecified vulnerability in Prestashop Customer Reassurance Block
blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy.
network
low complexity
prestashop
5.3
2023-11-08 CVE-2023-47109 Unspecified vulnerability in Prestashop Customer Reassurance Block
PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy.
network
low complexity
prestashop
8.1
2023-10-31 CVE-2023-36263 SQL Injection vulnerability in Prestashop Opartlimitquantity
Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection.
network
low complexity
prestashop CWE-89
critical
9.8
2023-09-28 CVE-2023-43663 Improper Privilege Management vulnerability in Prestashop
PrestaShop is an Open Source e-commerce web application.
network
low complexity
prestashop CWE-269
4.3
2023-09-28 CVE-2023-43664 Improper Privilege Management vulnerability in Prestashop
PrestaShop is an Open Source e-commerce web application.
network
low complexity
prestashop CWE-269
4.3
2023-09-20 CVE-2022-45448 Cross-site Scripting vulnerability in Prestashop M4 PDF
M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document crafting vulnerability.
network
low complexity
prestashop CWE-79
6.1
2023-09-20 CVE-2022-45447 Path Traversal vulnerability in Prestashop M4 PDF
M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerability.
network
low complexity
prestashop CWE-22
6.5