Prestashop Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Prestashop products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

5

In CISA KEV

0

Beyond CISA KEV

5

Sensor Observed

0

Virtual Patch Available

0

Prestashop KEVs Added by Year

Loading...

5 Prestashop KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2022-22897

A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for...

High Not in CISA 06 Jul 2025
CVE-2018-10942

modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to...

High Not in CISA 07 Jun 2025
CVE-2023-27640

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the...

High Not in CISA 01 Jun 2023
CVE-2023-27639

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the...

High Not in CISA 01 Jun 2023
CVE-2023-30194

Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().

High Not in CISA 10 May 2023

Common Vulnerability Classes (CWE)

  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 2
  • CWE-434 — Unrestricted Upload of File with Dangerous Type 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology