PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
High severity
GitHub Reviewed
Published
Mar 23, 2026
in
PrestaShop/PrestaShop
•
Updated Mar 27, 2026
Package
Affected versions
>= 9.0.0-alpha.1, < 9.1.0
< 8.2.5
Patched versions
9.1.0
8.2.5
Description
Published to the GitHub Advisory Database
Mar 25, 2026
Reviewed
Mar 25, 2026
Published by the National Vulnerability Database
Mar 26, 2026
Last updated
Mar 27, 2026
Impact
Multiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates.
Patches
Patched on 8.2.5 and 9.1.0
Workarounds
None
References
None
References