These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-92810 is a medium-severity vulnerability in the PrestaShop blockwishlist module, versions up to 3.0.2. The vulnerability allows authenticated customers to access private wishlist contents of other customers by supplying sequential wishlist identifiers to obtain valid share links. This issue arises from the module's failure to validate wishlist ownership properly. PrestaShop users with customer-fa [truncated]
CVE-2026-92809 debrief based on the supplied source corpus. The CVE record was published on 2026-09-16T21:17:30.570Z and has not been modified since then. PrestaShop psgdpr versions through 1.4.3 have a vulnerability allowing authenticated attackers to submit arbitrary customer identifiers, creating forged consent records and corrupting audit logs. This issue impacts PrestaShop administrators and security [truncated]
CVE-2026-84186 involves incorrect access control in PrestaShop's Tools::getRemoteAddr() function, allowing IP address spoofing via the X-Forwarded-For header when behind a reverse proxy, load balancer, or CDN. This could enable unauthenticated remote attackers to bypass IP-based controls, forge security and audit logs, and evade third-party mechanisms like geolocation checks.
The CVE-2026-54159 vulnerability affects PrestaShop's ps_facetedsearch module, versions 3.0.0 to 4.0.4. An unauthenticated attacker can inject a malicious serialized PHP object into the cache, leading to arbitrary PHP file creation and potential code execution. This issue is a critical vulnerability that can be exploited to run commands on the server. Users of PrestaShop's ps_facetedsearch module should b [truncated]
PrestaShop version 8.2.1 has a vulnerability related to incorrect sanitisation of elements. The 'Alias' parameter in the 'Update your address' function is inadequately validated, allowing attackers to inject malicious expressions. These expressions are executed when information is exported using the 'Get my data in CSV' tool. Successful exploitation could lead to unauthorised access to personal data. Orga [truncated]
CVE-2026-39079 describes a sensitive-information disclosure issue in the PrestaShop UPSShipping module, affecting versions through at least 2.4.0. A remote attacker may be able to access data exposed through /modules/upsshipping/logs/ and /modules/upsshipping/lib/UPSBaseApi.php. Because the issue centers on exposed files and logs rather than code execution, the primary concern is unintended leakage of con [truncated]