CVE-2026-33673 is a stored Cross-Site Scripting (XSS) vulnerability impacting PrestaShop e-commerce web applications in versions prior to 8.2.5 and 9.1.0. It allows an attacker with limited back-office access or a pre-existing vulnerability to inject malicious data into the database, potentially leading to information disclosure and data modification within the back-office. This vulnerability carries a CVSS score of 5.4 (Medium), indicating a network attack vector with low complexity but requiring user interaction. Currently, there is no public exploit code available, and it is not listed in CISA's Known Exploited Vulnerabilities catalog. However, the vulnerability has generated community discussion, with 44 mentions across various platforms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.2.5CPE matchmatch criteria | cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.1.0CPE matchmatch criteria | cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.