The 8 line is still maintained: fixes exist and ship. Everything depends on where you stand on the ladder below — a store updated to the last rung has no known unfixed core vulnerability.
| Severity | Vulnerability | Fixed by PrestaShop |
Blocked by the firewall |
PrestaSecure patch |
Closed in 8.1.7 |
|---|---|---|---|---|---|
| Critical | CVE-2026-44212 Unauthenticated stored XSS in AdminCustomerThreads via Contact Us form (PS 1.7 / 8.x) Fixed upstream in 8.2.6 | × not on your branch | ✓ confirmed | ✓ available | × still there |
| High | CVE-2024-21627 PrestaShop some attribute not escaped in Validate::isCleanHTML method Fixed upstream in 8.1.3 | × not on your branch | ✓ confirmed | – | ✓ closed |
| High | CVE-2026-33673 PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables Fixed upstream in 8.2.5 | × not on your branch | ✓ confirmed | – | × still there |
| High | no CVE reference CSV Formula Injection in exports (GHSA-w6j9-q9rq-wrqg) Fixed upstream in 8.2.8 | × not on your branch | ? not assessed | ✓ available | × still there |
| High | no CVE reference X-Forwarded-For IP spoofing (GHSA-2cr4-vw9p-pjvf) Fixed upstream in 8.2.8 | × not on your branch | ? not assessed | ✓ available | × still there |
| High | no CVE reference PrestaShop core — SSRF via import image URL (copyImg -> Tools::copy) Fixed upstream in 8.2.8 | × not on your branch | ? not assessed | ✓ available | × still there |
| High | no CVE reference PrestaShop core — CSV formula injection dans l'export legacy (AdminController::processExport) Fixed upstream in 99.0.0 | × not on your branch | ? not assessed | ✓ available | × still there |
| Medium | CVE-2023-39524 PrestaShop boolean SQL injection Fixed upstream in 8.1.0 | × not on your branch | ✓ confirmed | – | ✓ closed |
| Medium | CVE-2023-39525 PrestaShop path traversal Fixed upstream in 8.1.0 | × not on your branch | ✓ confirmed | – | ✓ closed |
| Medium | CVE-2023-39528 PrestaShop file access through path traversal Fixed upstream in 8.1.0 | × not on your branch | ✓ confirmed | – | ✓ closed |
| Medium | CVE-2023-39529 PrestaShop file deletion via attachment API Fixed upstream in 8.1.0 | × not on your branch | ✓ confirmed | – | ✓ closed |
| Medium | CVE-2023-39530 PrestaShop file deletion via CustomerMessage Fixed upstream in 8.1.0 | × not on your branch | ✓ confirmed | – | ✓ closed |
| Medium | CVE-2023-43663 PrestaShop allows users to uninstall modules from backoffice, even with low rights Fixed upstream in 8.1.2 | × not on your branch | ? not assessed | ✓ available | ✓ closed |
| Medium | CVE-2023-43664 PrestaShop allows employee without any access rights to list all installed modules Fixed upstream in 8.1.2 | × not on your branch | ? not assessed | ✓ available | ✓ closed |
| Medium | CVE-2024-21628 PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO) Fixed upstream in 8.1.3 | × not on your branch | ✓ confirmed | – | ✓ closed |
| Medium | CVE-2025-51586 Presta Shop vulnerable to email enumeration Fixed upstream in 8.2.3 | × not on your branch | ? not assessed | ✓ available | × still there |
| Medium | CVE-2026-25597 PrestaShop affected by time based enumeration in FO login form Fixed upstream in 8.2.4 | × not on your branch | ? not assessed | ✓ available | × still there |
| Medium | no CVE reference SQL injection via BO list filters (GHSA-whxq-pxj5-qq7v) Fixed upstream in 8.2.8 | × not on your branch | ? not assessed | ✓ available | × still there |
| Medium | no CVE reference BO notifications improper access control (GHSA-jf3w-9rmr-5rcr) Fixed upstream in 8.2.8 | × not on your branch | ? not assessed | ✓ available | × still there |
| Low | CVE-2026-33674 PrestaShop: Improper Use of Validation Framework Fixed upstream in 8.2.5 | × not on your branch | ? not assessed | – | × still there |
48 vulnerabilities found by our own team on commercial modules, across 41 different modules. None carries a public CVE reference: they exist nowhere else.
We publish neither the module name, nor the vector, nor how to exploit them. The vendor has not always shipped a fix, and the detail would expose every store running those modules — including stores that are not our customers. Our customers are protected without waiting for the flaw to become public.
Module concerned: · Vector:
It depends on your exact version, and the ladder at the top of the page shows it rung by rung. Because line 8 is still maintained, moving up a rung actually closes flaws — which is not the case on 1.6 and 1.7.
The last column of the register states it flaw by flaw, rather than as a blanket promise.
Because we have not audited their coverage yet. We would rather write that than display protection we have not verified. A flaw marked "confirmed" went through a real blocking test.
The core is only part of the risk. The vast majority of the advisories we track concern third-party modules, which no PrestaShop update fixes. On top of that come the malicious files dropped after an intrusion, which only a scan detects.
At every synchronisation of our advisory database. The figures are computed from the same source that feeds our scans, not typed by hand.
Move to the latest release of your line: it is free and it closes the core flaws. However, no PrestaShop update will fix the ones in your modules — that is where we come in.
Two-minute install. 14-day money-back, no questions asked.
Most of this catalogue comes from FriendsOfPresta and the GitHub Advisory database. We map it to the versions actually affected, we write the patches that are missing, and we test what our firewall blocks.