CVE-2025-61923Medium· 4.1▾ SunlitPrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the backoffice is missing validation on input resulting in a directory traversal and arbitrary file disclosur…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the backoffice is missing validation on input resulting in a directory traversal and arbitrary file disclosure. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
prestashop_checkout < 7.4.4.1prestashop_checkout >= 7.5.0.1, < 7.5.0.5prestashop_checkout >= 8.3.1.0, < 8.4.4.1prestashop_checkout >= 8.5.0.0, < 8.5.0.5prestashop_checkout >= 9.4.3.1, < 9.5.0.5Upgrade past the affected range:
prestashop_checkout 9.5.0.5Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61924Low· 3.8PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal
CVE-2025-61922Critical· 9.1PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal
CVE-2023-23946Medium· 6.2Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8
CVE-2022-37906Medium· 6.5An authenticated path traversal vulnerability exists in the ArubaOS command line interface
CVE-2024-13986High· 8.8Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface
CVE-2023-7260High· 7.5Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4