Technology · Packagist
prestashop/prestashop (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 23 vulnerabilities in prestashop/prestashop (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-51586, was published on 4 September 2025.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest prestashop/prestashop (Packagist) vulnerabilities
- CVE-2025-51586: Presta Shop vulnerable to email enumerationlowCVSS 3.1EPSS 0.8%
- CVE-2024-34717: Anonymous PrestaShop customer can download other customers' invoiceslowCVSS 3.1EPSS 0.5%
- CVE-2024-34716: PrestaShop cross-site scripting via customer contact form in FO, through file uploadlowCVSS 3.1EPSS 56.5%
- CVE-2024-26129: Path disclosure in JavaScript variablelowCVSS 3.1EPSS 0.6%
- CVE-2024-21628: PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO)lowCVSS 3.1EPSS 0.4%
- CVE-2023-43663: PrestaShop allows users to uninstall modules from backoffice, even with low rightslowCVSS 3.1EPSS 0.4%
- CVE-2023-43664: PrestaShop allows employee without any access rights to list all installed moduleslowCVSS 3.1EPSS 0.4%
- CVE-2023-39530: PrestaShop file deletion via CustomerMessagelowCVSS 3.1EPSS 0.9%
- CVE-2023-39529: PrestaShop file deletion via attachment APIlowCVSS 3.1EPSS 0.7%
- CVE-2023-39528: PrestaShop file access through path traversallowCVSS 3.1EPSS 0.8%
- CVE-2023-39525: PrestaShop path traversallowCVSS 3.1EPSS 0.9%
- CVE-2023-39524: PrestaShop boolean SQL injectionlowCVSS 3.1EPSS 0.7%
- CVE-2023-31508: Duplicate Advisory: PrestaShop Cross-site Scripting vulnerabilitylowCVSS 3.1
- CVE-2023-25170: Possible CSRF token fixationlowCVSS 3.1EPSS 0.2%
- CVE-2022-46158: PrestaShop has potential Information exposure in the upload directorylowCVSS 3EPSS 0.5%
- CVE-2022-31181: PrestaShop eval injection possible if shop vulnerable to SQL injectionlowCVSS 3.1EPSS 6.6%
- CVE-2022-36408: Duplicate Advisory GHSA-hrgx-p36p-89q4lowCVSS 3.1
- CVE-2019-11876: PrestaShop Cross-site Scripting vulnerabilitylowCVSS 3EPSS 0.9%
- CVE-2018-20717: PrestaShop PHP Object InjectionlowCVSS 3EPSS 2.7%
- CVE-2013-4791: PrestaShop Stored Cross-Site Scripting VulnerabilitylowCVSS 3.1EPSS 0.6%
- CVE-2012-20001: PrestaShop XSS VulnerabilitylowCVSS 3.1EPSS 0.8%
- CVE-2022-21686: Server Side Twig Template InjectionlowCVSS 3.1EPSS 1.8%
- CVE-2021-43789: SQL injection in prestashop/prestashoplowCVSS 3.1EPSS 4.6%
Most severe prestashop/prestashop (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-34716: PrestaShop cross-site scripting via customer contact form in FO, through file uploadlowCVSS 3.1EPSS 56.5%
- CVE-2022-31181: PrestaShop eval injection possible if shop vulnerable to SQL injectionlowCVSS 3.1EPSS 6.6%
- CVE-2021-43789: SQL injection in prestashop/prestashoplowCVSS 3.1EPSS 4.6%
- CVE-2022-21686: Server Side Twig Template InjectionlowCVSS 3.1EPSS 1.8%
- CVE-2023-39530: PrestaShop file deletion via CustomerMessagelowCVSS 3.1EPSS 0.9%
- CVE-2023-39525: PrestaShop path traversallowCVSS 3.1EPSS 0.9%
- CVE-2025-51586: Presta Shop vulnerable to email enumerationlowCVSS 3.1EPSS 0.8%
- CVE-2012-20001: PrestaShop XSS VulnerabilitylowCVSS 3.1EPSS 0.8%
- CVE-2023-39528: PrestaShop file access through path traversallowCVSS 3.1EPSS 0.8%
- CVE-2023-39529: PrestaShop file deletion via attachment APIlowCVSS 3.1EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/prestashop-prestashop.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "prestashop/prestashop (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/prestashop-prestashop, 28 September 2026.