You are up to date. You are not in the clear.

PrestaShop 1.6.1.24: 36 core flaws remain open.

1.6.1.24 is the last release of the 1.6 branch. These vulnerabilities were fixed by PrestaShop in later versions and never backported. Updating your branch to the end does not close them.

Coverage status

One mark per flaw — 27 out of 36 are neutralised on our side.

■ Blocked by our firewall, fixed by our patch, or both □ Neither blocked nor fixed to date — we say so too

The register

36 flaws · 27 covered by PrestaSecure
Severity Vulnerability Fixed
by PrestaShop
Blocked
by the firewall
PrestaSecure
patch
Critical CVE-2022-31181 PrestaShop eval injection possible if shop vulnerable to SQL injection Fixed upstream in 1.7.8.7 × not on your branch ? not assessed ✓ available
Critical CVE-2022-36408 CVE-2022-36408 Fixed upstream in 1.7.8.2 × not on your branch ≈ partial ✓ available
Critical CVE-2023-30839 SQL filter bypass leading to arbitrary write requests using "SQL Manager" Fixed upstream in 1.7.8.9 × not on your branch ? not assessed ✓ available
Critical CVE-2023-39526 PrestaShop SQL manager vulnerability Fixed upstream in 1.7.8.10 × not on your branch ? not assessed ✓ available
Critical CVE-2026-44212 PrestaShop has a stored XSS executable in customer service view Fixed upstream in 8.2.6 × not on your branch ? not assessed ✓ available
High CVE-2018-20717 PrestaShop PHP Object Injection Fixed upstream in 1.7.2.5 × not on your branch × out of scope ✓ available
High CVE-2020-15082 External control of configuration setting in the dashboard Fixed upstream in 1.7.6.6 × not on your branch ? not assessed ✓ available
High CVE-2020-26224 Improper Access Control with submitReorder function Fixed upstream in 1.7.6.9 × not on your branch ? not assessed ✓ available
High CVE-2020-4074 Improper Authentication Fixed upstream in 1.7.6.6 × not on your branch ? not assessed ✓ available
High CVE-2023-30545 Arbitrary file read via SQL injection Fixed upstream in 1.7.8.9 × not on your branch ? not assessed ✓ available
High CVE-2023-30838 Possible XSS injection through Validate::isCleanHTML method Fixed upstream in 1.7.8.9 × not on your branch ? not assessed ✓ available
High CVE-2023-39527 PrestaShop XSS injection through Validate::isCleanHTML method Fixed upstream in 1.7.8.10 × not on your branch ? not assessed ✓ available
High CVE-2024-21627 PrestaShop some attribute not escaped in Validate::isCleanHTML method Fixed upstream in 1.7.8.11 × not on your branch ? not assessed ✓ available
High CVE-2026-33673 PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables Fixed upstream in 8.2.5 × not on your branch ✓ confirmed ✓ available
High no CVE reference Client IP address can be spoofed through the X-Forwarded-For header Fixed upstream in 8.2.8 × not on your branch ? not assessed ✓ available
High no CVE reference Server-Side Request Forgery through image URLs in the CSV import Fixed upstream in 8.2.8 × not on your branch ? not assessed ✓ available
High no CVE reference PrestaShop core — CSV formula injection dans l'export legacy (AdminController::processExport) Fixed upstream in 99.0.0 × not on your branch ? not assessed ✓ available
Medium CVE-2020-11074 Stored XSS in AdminQuickAccesses Fixed upstream in 1.7.6.6 × not on your branch ? not assessed –
Medium CVE-2020-15079 Improper access control Fixed upstream in 1.7.6.6 × not on your branch ? not assessed –
Medium CVE-2020-5271 Reflected XSS with dashboard calendar Fixed upstream in 1.7.6.5 × not on your branch ? not assessed ✓ available
Medium CVE-2020-5272 Reflected XSS on Search page Fixed upstream in 1.7.6.5 × not on your branch ? not assessed ✓ available
Medium CVE-2020-5278 Reflected XSS on Exception page Fixed upstream in 1.7.6.5 × not on your branch ? not assessed ✓ available
Medium CVE-2020-5279 Improper Access Control Fixed upstream in 1.7.6.5 × not on your branch ? not assessed –
Medium CVE-2020-5287 Improper access control on customers search Fixed upstream in 1.7.6.5 × not on your branch ? not assessed –
Medium CVE-2021-21302 CSV Injection via csv export Fixed upstream in 1.7.7.2 × not on your branch ? not assessed –
Medium CVE-2021-21308 Improper session management for soft logout Fixed upstream in 1.7.7.2 × not on your branch ? not assessed –
Medium CVE-2023-39528 PrestaShop file access through path traversal Fixed upstream in 8.1.1 × not on your branch ✓ confirmed ✓ available
Medium CVE-2023-39529 PrestaShop file deletion via attachment API Fixed upstream in 8.1.1 × not on your branch ✓ confirmed ✓ available
Medium CVE-2023-39530 PrestaShop file deletion via CustomerMessage Fixed upstream in 8.1.1 × not on your branch ✓ confirmed ✓ available
Medium CVE-2023-43663 PrestaShop allows users to uninstall modules from backoffice, even with low rights Fixed upstream in 8.1.2 × not on your branch ? not assessed ✓ available
Medium CVE-2023-43664 PrestaShop allows employee without any access rights to list all installed modules Fixed upstream in 8.1.2 × not on your branch ? not assessed ✓ available
Medium CVE-2025-51586 Presta Shop vulnerable to email enumeration Fixed upstream in 8.2.3 × not on your branch ? not assessed –
Medium CVE-2026-25597 PrestaShop affected by time based enumeration in FO login form Fixed upstream in 8.2.4 × not on your branch ? not assessed –
Low CVE-2020-15081 Information exposure in the upload directory Fixed upstream in 1.7.6.6 × not on your branch ? not assessed ✓ available
Low CVE-2020-15161 Potential XSS injection with contact form Fixed upstream in 1.7.6.8 × not on your branch ? not assessed –
Low CVE-2020-15162 Stored XSS in upload files Fixed upstream in 1.7.6.8 × not on your branch ? not assessed ✓ available

What we will not publish

100 vulnerabilities found by our own team on commercial modules, across 82 different modules. None carries a public CVE reference: they exist nowhere else.

We publish neither the module name, nor the vector, nor how to exploit them. The vendor has not always shipped a fix, and the detail would expose every store running those modules — including stores that are not our customers. Our customers are protected without waiting for the flaw to become public.

Module concerned:                  · Vector:                       

100 discoveries
55 critical
99 already fixed
5 published

Frequently asked questions

  • Does PrestaShop 1.6 still receive security fixes?

    No. Support for the 1.6 branch has ended and 1.6.1.24 is its last release. The vulnerabilities listed on this page were fixed by PrestaShop in 1.7 and later, but none of those fixes were backported. No update will close them.

  • My 1.6 store runs fine — do I really need to migrate?

    Running and being exposed are two different things: a store can run perfectly for years while remaining attackable through a published flaw. Several vulnerabilities on this page are rated critical. There are two ways to close them: migrating, or applying our patches — we wrote them for some of these flaws, and they close the hole in the files of the version you already run. The register above states which ones, flaw by flaw.

  • What can PrestaSecure do if I cannot migrate yet?

    Our firewall blocks the attack request before it reaches your store, and our patches close some of the flaws directly in the files. The register above states, flaw by flaw, what is covered and what is not.

  • Does a PrestaSecure patch modify my site?

    It modifies the affected core files, in a targeted and reversible way: every patch is preceded by a backup and can be rolled back. Nothing is applied without your approval.

  • Are these vulnerabilities public?

    Yes, all of those on this page. They carry a CVE reference and are publicly documented. Listing them teaches an attacker nothing — but knowing which ones remain open on your version is useful to you.

These flaws will not close on their own

No update to your branch will fix them: they are permanent. Our patches close some of them without a version change, our firewall blocks the attack on others. Compare the three plans to see which one covers your situation.

Two-minute install. 14-day money-back, no questions asked.

Where this data comes from

Most of this catalogue comes from FriendsOfPresta and the GitHub Advisory database. We map it to the versions actually affected, we write the patches that are missing, and we test what our firewall blocks.

Updated on 7 October 2026 à 21h20 382 security advisories tracked
✓ Avis Vérifiés 5 avis clients ★★★★★ ★★★★★ 5/5