🎁 Current offer — SUPER25: 25% off your subscription, until August 31, 2026.
The PrestaShop core is not the main risk

261 known flaws across 220 commercial modules.

A perfectly up-to-date store stays exposed through its modules: no PrestaShop update fixes them, and not every vendor ships a patch.

79,3 %

that is 207 vulnerabilities out of 261 we block, fix, or both.

9 — firewall and patch
58 — PrestaSecure patch
140 — blocked by the firewall
54 — not covered to date

The latest patches written

last ten
20 Aug 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers Medium
9 Aug 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers High
8 Aug 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers Critical
8 Aug 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers Critical
7 Aug 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers Critical
7 Aug 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers Critical
7 Aug 2026 tvcmsvideotab Public advisory CVE-2023-39652 — patch written and verified on the affected versions Critical
7 Aug 2026 tvcmsblog Public advisory CVE-2023-39650 — patch written and verified on the affected versions Critical
7 Aug 2026 tvcmstestimonial Public advisory CVE-2023-39648 — patch written and verified on the affected versions Critical
7 Aug 2026 tvcmspaymenticon Public advisory CVE-2023-39645 — patch written and verified on the affected versions Critical

What we will not publish

48 vulnerabilities found by our own team on commercial modules, across 41 different modules. None carries a public CVE reference: they exist nowhere else.

We publish neither the module name, nor the vector, nor how to exploit them. The vendor has not always shipped a fix, and the detail would expose every store running those modules — including stores that are not our customers. Our customers are protected without waiting for the flaw to become public.

Module concerned:                  · Vector:                       

48 discoveries
28 critical
47 already fixed
0 published

And on the PrestaShop core side?

Core vulnerabilities depend on your version. An abandoned branch will never receive the fixes published since.

Frequently asked questions

  • How many module vulnerabilities do you track?

    The count at the top of this page is computed from the same database that feeds our scans, not typed by hand: it moves when an advisory is published or withdrawn.

  • What does "neutralised" mean exactly?

    That a flaw is covered in at least one of two ways: our firewall blocks the attack request before it reaches the store, or we wrote a patch that closes the flaw inside the module files. Vulnerabilities covered by neither appear hollow on the chart — we do not hide them.

  • Isn't a module patch just a module update?

    No, and that is the useful difference. Updating assumes the vendor released a fixed version, that it is compatible with your store, and that you can install it. Our patch works on the files of the version you already run: it closes the flaw without a version change, without regression risk on your theme, and it is reversible.

  • Why are some modules not named in the log?

    Because they are our own, unpublished discoveries. Naming the module would be pointing at a target: the vendor has not always shipped a fix, and every affected store would become vulnerable to the first researcher who looks. Our customers are protected without waiting for publication.

  • Are these figures current?

    They are recomputed at every synchronisation of our advisory database, and the timestamp at the bottom of the page shows the last one.

Which ones affect your store?

This page lists the flaws known across the market. Knowing which are actually installed on your store requires a scan of your files and modules.

Two-minute install. 14-day money-back, no questions asked.

Where this data comes from

Most of this catalogue comes from FriendsOfPresta and the GitHub Advisory database. We map it to the versions actually affected, we write the patches that are missing, and we test what our firewall blocks.

Updated on 23 August 2026 à 21h20 301 security advisories tracked
Avis Vérifiés 5 avis clients ★★★★★ ★★★★★ 5/5