Количество 2
Количество 2
CVE-2026-33673
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.
GHSA-35pf-37c6-jxjv
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-33673 PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available. | CVSS3: 7.6 | 0% Низкий | 5 месяцев назад | |
GHSA-35pf-37c6-jxjv PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables | CVSS3: 7.6 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу