CVE-2025-61924Low· 3.8▾ SunlitPrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). Th…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
prestashop_checkout < 7.4.4.1prestashop_checkout >= 7.5.0.1, < 7.5.0.5prestashop_checkout >= 8.3.1.0, < 8.4.4.1prestashop_checkout >= 8.5.0.0, < 8.5.0.5prestashop_checkout >= 9.4.3.1, < 9.5.0.5Upgrade past the affected range:
prestashop_checkout 9.5.0.5Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61923Medium· 4.1PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal
CVE-2025-61922Critical· 9.1PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal
CVE-2026-92809Medium· 4.3PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer
CVE-2026-92810Medium· 4.3PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier
CVE-2026-84186Medium· 6.9Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse pro…
CVE-2026-54159Critical· 10.0prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE