Mypresta develops a focused set of e-commerce extensions and modules for the PrestaShop platform, with its vulnerability footprint centered on file-upload and content-management features such as customer file uploads, photo galleries, and product imagery blocks. The observed weakness classes reflect common risks in user-generated-content handling: SQL injection in query construction and unrestricted file uploads that can introduce dangerous file types into the application layer. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mypresta over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19355CRITICAL modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a p | Nov 19, 2018 | 9.8 | 31 | NO | NO |
CVE-2021-40814CRITICAL The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection. | Sep 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2023-45386CRITICAL In the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via `extratabspro::searchcategory()`, `extratabspro::searchproduc | Oct 17, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-46351CRITICAL In the module mib < 1.6.1 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The methods `mib::getManufacturersByCategory()` has sensitive SQL calls that can be ex | Jan 19, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-46353CRITICAL In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The method TiconProduct::getTiconByProductAndTicon() | Dec 6, 2023 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mypresta.
Media articles that mention a CVE ID that affects a product developed by Mypresta — matched by CVE ID, not by vendor name.