Exposición de PrestaShop

CMS, Ecommerce
80
score de exposición
51.019
sitios usan
0
en explotación
8
críticos
Análisis Vexday

Com 61 CVEs catalogadas e nenhuma confirmada em exploração ativa no catálogo CISA KEV, o PrestaShop apresenta taxa de exploração abaixo da média geral, o que não elimina riscos relevantes. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que tende a ser subestimado, mas que em plataformas de e-commerce expõe dados de clientes e sessões administrativas a ataques de injeção de conteúdo. A CVE mais preocupante no momento é CVE-2024-34716, com score EPSS de 0,5617 — valor que indica probabilidade considerável de exploração em ambiente real e justifica priorização imediata de correção. As 8 vulnerabilidades de severidade crítica no histórico reforçam a necessidade de manter ciclos curtos de atualização, especialmente em instalações com módulos de terceiros.

CVEs

61 resultados
CVE-2023-39524MEDIUMPrestaShop vulnerable to boolean SQL injection in search product in BOEPSS 0.7%CVE-2020-15083MEDIUMReflected XSS when uploading an image in the Product page in PrestaShopEPSS 0.7%CVE-2024-26129MEDIUMPrestashop vulnerable to path disclosure in JavaScript variableEPSS 0.6%CVE-2020-11074MEDIUMStored XSS in PrestaShopEPSS 0.6%CVE-2020-15079MEDIUMImproper access control in PrestaShopEPSS 0.6%CVE-2024-34717MEDIUMAnonymous PrestaShop customer can download other customers' invoicesEPSS 0.5%CVE-2024-21627HIGHSome attribute not escaped in Validate::isCleanHTML methodEPSS 0.5%CVE-2023-39527HIGHPrestaShop XSS vulnerability through Validate::isCleanHTML methodEPSS 0.5%CVE-2024-30511MEDIUMWordPress FG PrestaShop to WooCommerce plugin <= 4.45.1 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2022-46158MEDIUMPotential Information exposure in the upload directory in PrestaShopEPSS 0.5%CVE-2023-43664MEDIUMEmployee without any access rights can list all installed modules in PrestashopEPSS 0.4%CVE-2024-21628MEDIUMXSS can be stored in DB from "add a message form" in order detail page (FO)EPSS 0.4%CVE-2023-43663MEDIUMImproper Privilege Management in PrestashopEPSS 0.3%CVE-2026-44212CRITICALPrestaShop: Stored XSS executable in customer service viewEPSS 0.3%CVE-2024-24837MEDIUMCross-Site Request Forgery (CSRF) vulnerability in FG PrestaShop, FG Drupal and FG Joomla WordPress pluginsEPSS 0.3%CVE-2026-33673HIGHPrestaShop has multiple stored XSS vulnerabilities via unprotected Template variablesEPSS 0.3%CVE-2026-25597MEDIUMPrestaShop has a time based enumeration in FO login formEPSS 0.3%CVE-2025-1230MEDIUMCross-Site Scripting (XSS) vulnerability in PrestashopEPSS 0.3%CVE-2026-33674LOWPrestaShop: Improper Use of Validation FrameworkEPSS 0.2%CVE-2023-25170MEDIUMPrestaShop has possible CSRF token fixationEPSS 0.2%