PatchSiren

PrestaShop CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL PrestaShop CVE published 2026-07-17

CVE-2026-54159

The CVE-2026-54159 vulnerability affects PrestaShop's ps_facetedsearch module, versions 3.0.0 to 4.0.4. An unauthenticated attacker can inject a malicious serialized PHP object into the cache, leading to arbitrary PHP file creation and potential code execution. This issue is a critical vulnerability that can be exploited to run commands on the server. Users of PrestaShop's ps_facetedsearch module should b [truncated]

MEDIUM PrestaShop CVE published 2026-07-13

CVE-2026-14846

PrestaShop version 8.2.1 has a vulnerability related to incorrect sanitisation of elements. The 'Alias' parameter in the 'Update your address' function is inadequately validated, allowing attackers to inject malicious expressions. These expressions are executed when information is exported using the 'Get my data in CSV' tool. Successful exploitation could lead to unauthorised access to personal data. Orga [truncated]

HIGH PrestaShop CVE published 2026-05-18

CVE-2026-39079

CVE-2026-39079 describes a sensitive-information disclosure issue in the PrestaShop UPSShipping module, affecting versions through at least 2.4.0. A remote attacker may be able to access data exposed through /modules/upsshipping/logs/ and /modules/upsshipping/lib/UPSBaseApi.php. Because the issue centers on exposed files and logs rather than code execution, the primary concern is unintended leakage of con [truncated]