Prestashop Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Prestashop products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
5
In CISA KEV
0
Beyond CISA KEV
5
Sensor Observed
0
Virtual Patch Available
0
Prestashop KEVs Added by Year
5 Prestashop KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-22897
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for... |
ApolloTheme AP PageBuilder | High | Not in CISA | 06 Jul 2025 |
|
CVE-2018-10942
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to... |
Attribute Wizard addon | High | Not in CISA | 07 Jun 2025 |
|
CVE-2023-27640
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the... |
Custom Product Designer | High | Not in CISA | 01 Jun 2023 |
|
CVE-2023-27639
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the... |
Custom Product Designer | High | Not in CISA | 01 Jun 2023 |
|
CVE-2023-30194
Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). |
posstaticfooter | High | Not in CISA | 10 May 2023 |
Common Vulnerability Classes (CWE)
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 2
- CWE-434 — Unrestricted Upload of File with Dangerous Type 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology