Vulnerabilities > Prestashop > Prestashop > 1.6

DATE CVE VULNERABILITY TITLE RISK
2020-07-02 CVE-2020-11074 Cross-site Scripting vulnerability in Prestashop
In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick access item.
network
low complexity
prestashop CWE-79
5.4
2019-12-05 CVE-2019-19595 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.
network
low complexity
adobe prestashop CWE-434
7.5
2019-12-05 CVE-2019-19594 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.
network
low complexity
adobe prestashop CWE-434
7.5