Prestashop vendor intelligence
Prestashop Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Prestashop products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 5
- Known exploited vulnerabilities affecting Prestashop products
- In CISA KEV
- 0
- Records also listed in the official catalog
- Beyond CISA KEV
- 5
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Prestashop KEVs with sensor-observed exploitation activity
The catalog gap matters for Prestashop exposure
Five of the five exploited Prestashop CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 100% of this vendor portfolio.
- 0%
- Covered by CISA
- 100%
- Beyond CISA
- 4
- Product families
Attested Prestashop CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-22897
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for... |
ApolloTheme AP PageBuilder | High | Beyond CISA | 06 Jul 2025 |
|
CVE-2018-10942
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to... |
Attribute Wizard addon | High | Beyond CISA | 07 Jun 2025 |
|
CVE-2023-27640
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the... |
Custom Product Designer | High | Beyond CISA | 01 Jun 2023 |
|
CVE-2023-27639
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the... |
Custom Product Designer | High | Beyond CISA | 01 Jun 2023 |
|
CVE-2023-30194
Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). |
posstaticfooter | High | Beyond CISA | 10 May 2023 |
No Prestashop CVEs match this search or filter.
Showing 5 of 5 Prestashop known exploited vulnerabilities.
Recurring weakness patterns
Limitation, neutralization, and unrestricted upload account for five mapped occurrences across this Prestashop KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.