Presto Changeo maintains a narrowly scoped portfolio of web-based content and site-management tools, including Attribute Grid, Canada Post integration services, and test site creators. The vendor's vulnerability surface reflects the input-handling and web-application architecture characteristic of these platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Presto Changeo over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-43981CRITICAL Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php. | Oct 5, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-43983CRITICAL Presto Changeo attributegrid up to 2.0.3 was discovered to contain a SQL injection vulnerability via the component disable_json.php. | Oct 5, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-43980CRITICAL Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php. | Oct 2, 2023 | 9.8 | 24 | NO | NO |
CVE-2012-5799MEDIUM The Canada Post (aka CanadaPost) module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of th | Nov 4, 2012 | 5.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Presto Changeo.
Media articles that mention a CVE ID that affects a product developed by Presto Changeo — matched by CVE ID, not by vendor name.