PrestaShop Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in PrestaShop versions prior to 8.2.5 and 9.1.0. This vulnerability allows an attacker with limited back-office access or knowledge of a pre-existing vulnerability to inject data into the database. The injected data can then be exploited by manipulating unprotected variables in back-office templates.

Impact

Exploitation of this vulnerability allows for multiple stored cross-site scripting issues in the back office, where injected scripts are executed in the context of the user.

Remediation

Users can upgrade to PrestaShop versions 8.2.5 or 9.1.0 to address this vulnerability.

Added: Mar 26, 2026, 10:28 PM
Updated: Mar 26, 2026, 10:28 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
1.7
exploitability
6.0
remediation
7.7
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.