Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Prestashop

First CVE: Dec 31, 2008Active for: 18 yearsTotal CVEs: 128
47.4
VTI Score
High

Prestashop operates a widely deployed open-source e-commerce platform and related shopping-cart extensions that serve merchants and small-to-medium businesses globally, creating a substantial attack surface across numerous online storefronts. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting both the platform's internet-facing role and its appeal as a target for payment-theft and customer-data compromise. The exposure recurs across the core platform and its satellite modules such as checkout extensions, tag management, and PDF generation tools, concentrating in application-layer weakness classes including cross-site scripting, SQL injection, improper access control, and path-traversal flaws that are characteristic of web-application codebases. Defenders should treat Prestashop advisories as high-priority patches for any deployed instance, since the platform's open-source nature and e-commerce context make it a high-value target for active threat actors. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
128
Total CVEs
More Total CVEs than 99% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Prestashop over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2008
17 years ago
Most Recent CVE
Mar 26, 2026
122 days ago

Products(30 total)

Top CVEs

Signals from CVEs in this vendor scope (128 CVEs).

128 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-8823CRITICAL
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to e
Mar 28, 20189.868NOYES
CVE-2022-31101HIGH
prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection.
Jun 27, 20228.859NOYES
CVE-2023-30194CRITICAL
Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().
May 10, 20239.858NOYES
CVE-2018-19126CRITICAL
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.
Nov 9, 20189.854NOYES
CVE-2024-34716MEDIUM
PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is prese
May 14, 20246.152NONO
CVE-2021-3110CRITICAL
The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.
Jan 20, 20219.852NOYES
CVE-2018-13784CRITICAL
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.
Jul 9, 20189.149NOYES
CVE-2022-31181CRITICAL
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call
Aug 1, 20229.844NOYES
CVE-2018-10942CRITICAL
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploadin
May 10, 20189.844NOYES
CVE-2023-30192CRITICAL
Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().
May 12, 20239.842NOYES
View all 128 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products128 CVEs
55%
16%
27%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network118 (92.2%)
Unknown10 (7.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low116 (90.6%)
High2 (1.6%)
Unknown10 (7.8%)
User Interaction
None79 (61.7%)
Unknown10 (7.8%)
Required39 (30.5%)
Privileges Required
Low29 (22.7%)
High4 (3.1%)
None85 (66.4%)
Unknown10 (7.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (128 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
10 CVEs
7.8% of CVEs· 96th percentile
ExploitDB
9 CVEs
7.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Prestashop.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Prestashop — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Prestashop's Products

View all 3 CNAs →

Top CWEs