PrestaShop Time-Based User Enumeration Vulnerability in Authentication

Vulnerability

A time-based user enumeration vulnerability has been identified in the authentication functionality of PrestaShop. This issue affects versions prior to 8.2.4 and 9.0.3. The vulnerability allows attackers to determine the existence of customer accounts by measuring response times during the login process.

Impact

Exploitation of this vulnerability could lead to unauthorized account enumeration, allowing attackers to verify the existence of user accounts.

Remediation

Users can upgrade to PrestaShop versions 8.2.4 or 9.0.3 to address this vulnerability.

Added: Feb 6, 2026, 9:26 PM
Updated: Feb 6, 2026, 10:11 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
0.6
exploitability
8.3
remediation
7.7
relevance
2.8
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.