PrestaShop has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 5.6 (medium), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.6
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Products
- PrestaShop 1
- blockwishlist 1
- prestashop/ps_facetedsearch 1
- psgdpr 1
Worst active — by depth score
CVE-2026-54159Critical· 10.0prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE55CVE-2026-84186Medium· 6.9Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse pro…38CVE-2026-92810Medium· 4.3PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier36CVE-2026-92809Medium· 4.3PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer36
PrestaShop vulnerabilities
CVEs affecting PrestaShop, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-92809Medium· 4.3PoCPrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer
PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for …
CVE-2026-92810Medium· 4.3PoCPrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier
PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential…
CVE-2026-84186Medium· 6.9Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse pro…
Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse pro…
CVE-2026-54159Critical· 10.0prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE