Prestashop operates a widely deployed open-source e-commerce platform and related shopping-cart extensions that serve merchants and small-to-medium businesses globally, creating a substantial attack surface across numerous online storefronts. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting both the platform's internet-facing role and its appeal as a target for payment-theft and customer-data compromise. The exposure recurs across the core platform and its satellite modules such as checkout extensions, tag management, and PDF generation tools, concentrating in application-layer weakness classes including cross-site scripting, SQL injection, improper access control, and path-traversal flaws that are characteristic of web-application codebases. Defenders should treat Prestashop advisories as high-priority patches for any deployed instance, since the platform's open-source nature and e-commerce context make it a high-value target for active threat actors. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prestashop over time
Signals from CVEs in this vendor scope (128 CVEs).
128 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8823CRITICAL modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to e | Mar 28, 2018 | 9.8 | 68 | NO | YES |
CVE-2022-31101HIGH prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. | Jun 27, 2022 | 8.8 | 59 | NO | YES |
CVE-2023-30194CRITICAL Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). | May 10, 2023 | 9.8 | 58 | NO | YES |
CVE-2018-19126CRITICAL PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload. | Nov 9, 2018 | 9.8 | 54 | NO | YES |
CVE-2024-34716MEDIUM PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is prese | May 14, 2024 | 6.1 | 52 | NO | NO |
CVE-2021-3110CRITICAL The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter. | Jan 20, 2021 | 9.8 | 52 | NO | YES |
CVE-2018-13784CRITICAL PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php. | Jul 9, 2018 | 9.1 | 49 | NO | YES |
CVE-2022-31181CRITICAL PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call | Aug 1, 2022 | 9.8 | 44 | NO | YES |
CVE-2018-10942CRITICAL modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploadin | May 10, 2018 | 9.8 | 44 | NO | YES |
CVE-2023-30192CRITICAL Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find(). | May 12, 2023 | 9.8 | 42 | NO | YES |
Signals from CVEs in this vendor scope (128 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prestashop.
Media articles that mention a CVE ID that affects a product developed by Prestashop — matched by CVE ID, not by vendor name.