On this line, updating is enough — provided you go all the way

PrestaShop 8.0.5: 21 core flaws remain open.

The 8 line is still maintained: fixes exist and ship. Everything depends on where you stand on the ladder below — a store updated to the last rung has no known unfixed core vulnerability.

  • 8.0.5 21 21 core flaw(s) still open, 21 of them neutralised by PrestaSecure.
  • 8.1.7 12 12 core flaw(s) still open, 12 of them neutralised by PrestaSecure.
  • 8.2.6 7 7 core flaw(s) still open, 7 of them neutralised by PrestaSecure.

What remains open on 8.0.5

21 flaws · 21 covered by PrestaSecure
Severity Vulnerability Fixed
by PrestaShop
Blocked
by the firewall
PrestaSecure
patch
Closed in 8.1.7
Critical CVE-2026-44212 PrestaShop has a stored XSS executable in customer service view Fixed upstream in 8.2.6 × not on your branch ✓ confirmed ✓ available × still there
High CVE-2024-21627 PrestaShop some attribute not escaped in Validate::isCleanHTML method Fixed upstream in 8.1.3 × not on your branch ✓ confirmed ✓ available ✓ closed
High CVE-2026-33673 PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables Fixed upstream in 8.2.5 × not on your branch ✓ confirmed ✓ available × still there
High no CVE reference Formula injection in CSV exports (CSV injection) Fixed upstream in 8.2.8 × not on your branch ? not assessed ✓ available × still there
High no CVE reference Client IP address can be spoofed through the X-Forwarded-For header Fixed upstream in 8.2.8 × not on your branch ? not assessed ✓ available × still there
High no CVE reference Server-Side Request Forgery through image URLs in the CSV import Fixed upstream in 8.2.8 × not on your branch ? not assessed ✓ available × still there
High no CVE reference PrestaShop core — CSV formula injection dans l'export legacy (AdminController::processExport) Fixed upstream in 99.0.0 × not on your branch ? not assessed ✓ available × still there
High no CVE reference PrestaShop core — jeton de réinitialisation de mot de passe prévisible (prise de compte client) × not on your branch ? not assessed ✓ available × still there
Medium CVE-2023-39524 PrestaShop boolean SQL injection Fixed upstream in 8.1.1 × not on your branch ✓ confirmed ✓ available ✓ closed
Medium CVE-2023-39525 PrestaShop path traversal Fixed upstream in 8.1.1 × not on your branch ✓ confirmed ✓ available ✓ closed
Medium CVE-2023-39528 PrestaShop file access through path traversal Fixed upstream in 8.1.1 × not on your branch ✓ confirmed ✓ available ✓ closed
Medium CVE-2023-39529 PrestaShop file deletion via attachment API Fixed upstream in 8.1.1 × not on your branch ✓ confirmed ✓ available ✓ closed
Medium CVE-2023-39530 PrestaShop file deletion via CustomerMessage Fixed upstream in 8.1.1 × not on your branch ✓ confirmed ✓ available ✓ closed
Medium CVE-2023-43663 PrestaShop allows users to uninstall modules from backoffice, even with low rights Fixed upstream in 8.1.2 × not on your branch ? not assessed ✓ available ✓ closed
Medium CVE-2023-43664 PrestaShop allows employee without any access rights to list all installed modules Fixed upstream in 8.1.2 × not on your branch ? not assessed ✓ available ✓ closed
Medium CVE-2024-21628 PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO) Fixed upstream in 8.1.3 × not on your branch ✓ confirmed ✓ available ✓ closed
Medium CVE-2025-51586 Presta Shop vulnerable to email enumeration Fixed upstream in 8.2.3 × not on your branch ? not assessed ✓ available × still there
Medium CVE-2026-25597 PrestaShop affected by time based enumeration in FO login form Fixed upstream in 8.2.4 × not on your branch ? not assessed ✓ available × still there
Medium no CVE reference SQL injection through back-office list filters Fixed upstream in 8.2.8 × not on your branch ? not assessed ✓ available × still there
Medium no CVE reference Improper access control on the back-office notifications endpoint exposes customer data Fixed upstream in 8.2.8 × not on your branch ? not assessed ✓ available × still there
Low CVE-2026-33674 PrestaShop: Improper Use of Validation Framework Fixed upstream in 8.2.5 × not on your branch ? not assessed ✓ available × still there

What we will not publish

100 vulnerabilities found by our own team on commercial modules, across 82 different modules. None carries a public CVE reference: they exist nowhere else.

We publish neither the module name, nor the vector, nor how to exploit them. The vendor has not always shipped a fix, and the detail would expose every store running those modules — including stores that are not our customers. Our customers are protected without waiting for the flaw to become public.

Module concerned:                  · Vector:                       

100 discoveries
55 critical
99 already fixed
5 published

Frequently asked questions

Your core will be clean. Your modules will not.

Move to the latest release of your line: it is free and it closes the core flaws. However, no PrestaShop update will fix the ones in your modules — that is where we come in.

Two-minute install. 14-day money-back, no questions asked.

Where this data comes from

Most of this catalogue comes from FriendsOfPresta and the GitHub Advisory database. We map it to the versions actually affected, we write the patches that are missing, and we test what our firewall blocks.

Updated on 7 October 2026 à 21h20 382 security advisories tracked
✓ Avis Vérifiés 5 avis clients ★★★★★ ★★★★★ 5/5