The PrestaShop core is not the main risk

312 known flaws across 250 commercial modules.

A perfectly up-to-date store stays exposed through its modules: no PrestaShop update fixes them, and not every vendor ships a patch.

84,2 %

that is 263 vulnerabilities out of 312 we block, fix, or both.

34 — firewall and patch
114 — PrestaSecure patch
115 — blocked by the firewall
49 — not covered to date

The latest patches written

last ten
7 Oct 2026 creativepopup Public advisory CVE-2023-45381 — patch written and verified on the affected versions Critical
5 Oct 2026 tvcmsvideotab Public advisory CVE-2023-39652 — patch written and verified on the affected versions Critical
5 Oct 2026 tvcmstestimonial Public advisory CVE-2023-39648 — patch written and verified on the affected versions Critical
5 Oct 2026 tvcmspaymenticon Public advisory CVE-2023-39645 — patch written and verified on the affected versions Critical
5 Oct 2026 tvcmscategoryslider Public advisory CVE-2023-39649 — patch written and verified on the affected versions Critical
5 Oct 2026 tvcmscategoryproduct Public advisory CVE-2023-39647 — patch written and verified on the affected versions Critical
5 Oct 2026 tvcmscategorychainslider Public advisory CVE-2023-39646 — patch written and verified on the affected versions Critical
5 Oct 2026 tvcmsbrandlist Public advisory CVE-2023-39651 — patch written and verified on the affected versions Critical
5 Oct 2026 ecgeneratebarcode Public advisory CVE-2024-24310 — patch written and verified on the affected versions High
5 Oct 2026 customexporter Public advisory CVE-2023-30199 — patch written and verified on the affected versions High

What we will not publish

100 vulnerabilities found by our own team on commercial modules, across 82 different modules. None carries a public CVE reference: they exist nowhere else.

We publish neither the module name, nor the vector, nor how to exploit them. The vendor has not always shipped a fix, and the detail would expose every store running those modules — including stores that are not our customers. Our customers are protected without waiting for the flaw to become public.

Module concerned:                  · Vector:                       

100 discoveries
55 critical
99 already fixed
5 published

And on the PrestaShop core side?

Core vulnerabilities depend on your version. An abandoned branch will never receive the fixes published since.

Frequently asked questions

  • How many module vulnerabilities do you track?

    The count at the top of this page is computed from the same database that feeds our scans, not typed by hand: it moves when an advisory is published or withdrawn.

  • What does "neutralised" mean exactly?

    That a flaw is covered in at least one of two ways: our firewall blocks the attack request before it reaches the store, or we wrote a patch that closes the flaw inside the module files. Vulnerabilities covered by neither appear hollow on the chart — we do not hide them.

  • Isn't a module patch just a module update?

    No, and that is the useful difference. Updating assumes the vendor released a fixed version, that it is compatible with your store, and that you can install it. Our patch works on the files of the version you already run: it closes the flaw without a version change, without regression risk on your theme, and it is reversible.

  • Why are some modules not named in the log?

    Because they are our own, unpublished discoveries. Naming the module would be pointing at a target: the vendor has not always shipped a fix, and every affected store would become vulnerable to the first researcher who looks. Our customers are protected without waiting for publication.

  • Are these figures current?

    They are recomputed at every synchronisation of our advisory database, and the timestamp at the bottom of the page shows the last one.

Which ones affect your store?

This page lists the flaws known across the market. Knowing which are actually installed on your store requires a scan of your files and modules.

Two-minute install. 14-day money-back, no questions asked.

Where this data comes from

Most of this catalogue comes from FriendsOfPresta and the GitHub Advisory database. We map it to the versions actually affected, we write the patches that are missing, and we test what our firewall blocks.

Updated on 7 October 2026 à 21h20 382 security advisories tracked
✓ Avis Vérifiés 5 avis clients ★★★★★ ★★★★★ 5/5