Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w9f3-qc75-qgx9 | PrestaShop has a stored XSS executable in customer service view |
Fri, 15 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Prestashop
Prestashop prestashop |
|
| Vendors & Products |
Prestashop
Prestashop prestashop |
Thu, 14 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. This vulnerability is fixed in 8.2.6 and 9.1.1. | |
| Title | PrestaShop: Stored XSS executable in customer service view | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-15T13:34:09.904Z
Reserved: 2026-05-05T15:13:47.571Z
Link: CVE-2026-44212
Updated: 2026-05-15T13:34:04.403Z
Status : Deferred
Published: 2026-05-14T21:16:46.540
Modified: 2026-05-15T14:30:03.170
Link: CVE-2026-44212
No data.
OpenCVE Enrichment
Updated: 2026-05-14T22:30:25Z
Github GHSA