VulnSea

PrestaShop has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 5.6 (medium), with 1 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.6
Publish → KEV
Last 90 days
4 prev 0

Products

  • PrestaShop 1
  • blockwishlist 1
  • prestashop/ps_facetedsearch 1
  • psgdpr 1
4
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

PrestaShop vulnerabilities

CVEs affecting PrestaShop, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-92809Medium· 4.3PoC
6d ago

PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer

PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for …

TwilightPrestaShop · psgdprEPSS 0.20%via NVD
CVE-2026-92810Medium· 4.3PoC
6d ago

PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier

PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential…

TwilightPrestaShop · blockwishlistEPSS 0.20%via NVD
CVE-2026-84186Medium· 6.9
2w ago

Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse pro…

Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse pro…

SunlitPrestaShop · PrestaShopEPSS 0.35%via NVD
CVE-2026-54159Critical· 10.0
2mo ago

prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE

prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE

Midnightprestashop · prestashop/ps_facetedsearchEPSS 0.75%via GHSA
PrestaShop vulnerabilities (CVEs) · VulnSea