The PrestaShop core is not the main risk

306 known flaws across 246 commercial modules.

A perfectly up-to-date store stays exposed through its modules: no PrestaShop update fixes them, and not every vendor ships a patch.

83,3 %

that is 255 vulnerabilities out of 306 we block, fix, or both.

11 — firewall and patch
106 — PrestaSecure patch
138 — blocked by the firewall
51 — not covered to date

The latest patches written

last ten
11 Sep 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers High
11 Sep 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers Critical
11 Sep 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers Critical
9 Sep 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers Low
8 Sep 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers High
8 Sep 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers High
8 Sep 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers High
8 Sep 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers High
8 Sep 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers Critical
8 Sep 2026                PrestaSecure discovery — module undisclosed, patch shipped to our customers High

What we will not publish

93 vulnerabilities found by our own team on commercial modules, across 78 different modules. None carries a public CVE reference: they exist nowhere else.

We publish neither the module name, nor the vector, nor how to exploit them. The vendor has not always shipped a fix, and the detail would expose every store running those modules — including stores that are not our customers. Our customers are protected without waiting for the flaw to become public.

Module concerned:                  · Vector:                       

93 discoveries
52 critical
92 already fixed
4 published

And on the PrestaShop core side?

Core vulnerabilities depend on your version. An abandoned branch will never receive the fixes published since.

Frequently asked questions

  • How many module vulnerabilities do you track?

    The count at the top of this page is computed from the same database that feeds our scans, not typed by hand: it moves when an advisory is published or withdrawn.

  • What does "neutralised" mean exactly?

    That a flaw is covered in at least one of two ways: our firewall blocks the attack request before it reaches the store, or we wrote a patch that closes the flaw inside the module files. Vulnerabilities covered by neither appear hollow on the chart — we do not hide them.

  • Isn't a module patch just a module update?

    No, and that is the useful difference. Updating assumes the vendor released a fixed version, that it is compatible with your store, and that you can install it. Our patch works on the files of the version you already run: it closes the flaw without a version change, without regression risk on your theme, and it is reversible.

  • Why are some modules not named in the log?

    Because they are our own, unpublished discoveries. Naming the module would be pointing at a target: the vendor has not always shipped a fix, and every affected store would become vulnerable to the first researcher who looks. Our customers are protected without waiting for publication.

  • Are these figures current?

    They are recomputed at every synchronisation of our advisory database, and the timestamp at the bottom of the page shows the last one.

Which ones affect your store?

This page lists the flaws known across the market. Knowing which are actually installed on your store requires a scan of your files and modules.

Two-minute install. 14-day money-back, no questions asked.

Where this data comes from

Most of this catalogue comes from FriendsOfPresta and the GitHub Advisory database. We map it to the versions actually affected, we write the patches that are missing, and we test what our firewall blocks.

Updated on 12 September 2026 à 03h20 346 security advisories tracked
Avis Vérifiés 5 avis clients ★★★★★ ★★★★★ 5/5