Myprestamodules develops a narrowly scoped but well-represented line of import/export and catalog-management modules for PrestaShop, positioned among the more prominent module vendors in the landscape. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across products through high-impact weakness classes including SQL injection, information exposure, code injection, and path traversal that reflect the data-handling and privilege-control demands of server-side import and administrative functionality. Defenders should treat updates to these modules as high-priority, particularly for internet-connected shops; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Myprestamodules over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39677HIGH MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php. | Sep 20, 2023 | 7.5 | 47 | NO | YES |
CVE-2023-45387CRITICAL In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection via `ex | Nov 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-46357CRITICAL In the module "Cross Selling in Modal Cart" (motivationsale) < 3.5.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `motivationsaleDataModel::ge | Nov 22, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-26858CRITICAL SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget compo | Mar 31, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-25847CRITICAL SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to esc | Mar 3, 2024 | 9.8 | 25 | NO | NO |
CVE-2023-46349CRITICAL In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpda | Nov 27, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-39675CRITICAL SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php. | Sep 20, 2023 | 9.8 | 25 | NO | NO |
CVE-2024-25846CRITICAL In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php. | Feb 27, 2024 | 9.1 | 24 | NO | NO |
CVE-2023-40923HIGH MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters. | Nov 15, 2023 | 8.8 | 23 | NO | NO |
CVE-2024-28396HIGH An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component. | Mar 20, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Myprestamodules.
Media articles that mention a CVE ID that affects a product developed by Myprestamodules — matched by CVE ID, not by vendor name.