CVE-2026-33673
🟡 Monitoruj
W PrestaShop występuje podatność na XSS w BO, co pozwala na zdalne wykonanie kodu.
CVSS
7.6
EPSS
0.0%
Exploit
none
Vendor
Opis źródłowy (NVD)
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.
xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.6 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.0% |
| Opublikowano (NVD) | 2026-03-26 22:16:30 UTC |
| Ostatnia modyfikacja (NVD) | 2026-03-30 13:26:50 UTC |
Referencje
- https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.5 (security-advisories@github.com)
- https://github.com/PrestaShop/PrestaShop/releases/tag/9.1.0 (security-advisories@github.com)
- https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-35pf-37c6-jxjv (security-advisories@github.com)