Exposición de PrestaShop

CMS, Ecommerce
80
score de exposición
51.019
sitios usan
0
en explotación
8
críticos
Análisis Vexday

Com 61 CVEs catalogadas e nenhuma confirmada em exploração ativa no catálogo CISA KEV, o PrestaShop apresenta taxa de exploração abaixo da média geral, o que não elimina riscos relevantes. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que tende a ser subestimado, mas que em plataformas de e-commerce expõe dados de clientes e sessões administrativas a ataques de injeção de conteúdo. A CVE mais preocupante no momento é CVE-2024-34716, com score EPSS de 0,5617 — valor que indica probabilidade considerável de exploração em ambiente real e justifica priorização imediata de correção. As 8 vulnerabilidades de severidade crítica no histórico reforçam a necessidade de manter ciclos curtos de atualização, especialmente em instalações com módulos de terceiros.

CVEs

61 resultados
CVE-2020-5272MEDIUMReflected XSS on Search page of PrestaShopEPSS 0.8%CVE-2020-5270MEDIUMOpen redirection when using back parameter of PrestaShopEPSS 0.8%CVE-2020-15162MEDIUMStored XSS in PrestaShopEPSS 0.8%CVE-2020-5279MEDIUMImproper Access Control for certain legacy controller in PrestaShopEPSS 0.8%CVE-2020-5269MEDIUMReflected XSS on AdminFeatures page of PrestaShopEPSS 0.8%CVE-2020-5271MEDIUMReflected XSS with dashboard calendar of PrestaShopEPSS 0.8%CVE-2020-5276MEDIUMReflected XSS on AdminCarts page of PrestaShopEPSS 0.8%CVE-2020-5278MEDIUMReflected XSS on Exception page of PrestaShopEPSS 0.8%CVE-2020-5285MEDIUMReflected XSS with back parameter in PrestaShopEPSS 0.8%CVE-2023-39528MEDIUMPrestaShop vulnerable to file reading through path traversalEPSS 0.8%CVE-2023-28839CRITICALImproper neutralization in an SQL query in ShoppingfeedEPSS 0.8%CVE-2020-5264MEDIUMReflected XSS in security compromised page of PrestaShopEPSS 0.7%CVE-2020-5265MEDIUMReflected XSS on AdminAttributesGroups page of PrestaShopEPSS 0.7%CVE-2023-39529MEDIUMPrestaShop vulnerable to file deletion via attachment APIEPSS 0.7%CVE-2021-21398MEDIUMPossible XSS injection through DataColumn Grid classEPSS 0.7%CVE-2023-6921CRITICALSQL Injection in PrestaShop Google IntegratorEPSS 0.7%CVE-2020-5293MEDIUMImproper access control on product page with combinations, attachments and specific prices in PrestaShopEPSS 0.7%CVE-2020-5288MEDIUMImproper access control on product attributes page in PrestaShopEPSS 0.7%CVE-2020-5287MEDIUMImproper access control on customers search in PrestaShopEPSS 0.7%CVE-2020-5286MEDIUMReflected XSS related in import page in PrestaShopEPSS 0.7%