Friends-Of-Presta Security Advisories
Cybersecurity GlossaryAbout
    • Mar 15, 2023 • #module • critical (9.8)

      [CVE-2023-27569]-[CVE-2023-27570] Improper neutralization of SQL parameters in Profileo : Tracking et Conversions (eo_tags) module for PrestaShop

      In the module Tracking et Conversions (eo_tags) prior to version 1.4.19, an anonymous user can perform an SQL injection attack.

    • Mar 14, 2023 • #modules • critical (9.8)

      [CVE-2023-25206] Multiple improper neutralization of SQL parameters in ws_productreviews module for PrestaShop

      In the module “Advanced Reviews: Photos, Reminder, Google Snippets” (ws_productreviews), an anonymous user can perform SQL injection in affected versions. 3.6.2 fixed vulnerabilities.

    • Mar 13, 2023 • #modules • critical (9.8)

      [CVE-2023-29630] Blind SQL injection vulnerability in Jms Vertical MegaMenu (jmsvermegamenu) PrestaShop module

      The module Jms Vertical MegaMenu (jmsvermegamenu) from Joommasters contains a Blind SQL injection vulnerability. This module is for the PrestaShop e-commerce platform and mainly provided with joo masters PrestaShop themes

    • Mar 13, 2023 • #modules • critical (9.8)

      [CVE-2023-29629] Blind SQL injection vulnerability in Jms Theme Layout (jmsthemelayout) PrestaShop module

      The module Jms Theme Layout (jmsthemelayout) from Joommasters contains a Blind SQL injection vulnerability. This module is for the PrestaShop e-commerce platform and mainly provided with joo masters PrestaShop themes

    • Mar 13, 2023 • #modules • critical (9.8)

      [CVE-2023-29631] Unrestricted upload vulnerability in Jms Slider (jmsslider) PrestaShop module

      The module Jms Slider (jmsslider) from Joommasters contains an unrestricted upload of file with dangerous type vulnerability. This module is for the PrestaShop e-commerce platform and mainly provided with joo masters PrestaShop themes

    • Mar 13, 2023 • #modules • critical (9.8)

      [CVE-2023-29632] Blind SQL injection vulnerability in Jms Page Builder (jmspagebuilder) PrestaShop module

      The module Jms Page Builder (jmspagebuilder) from Joommasters contains a Blind SQL injection vulnerability. This module is for the PrestaShop e-commerce platform and mainly provided with joo masters PrestaShop themes

    • Mar 13, 2023 • #modules • critical (9.8)

      [CVE-2023-29630] Blind SQL injection vulnerability in Jms MegaMenu (jmsmegamenu) PrestaShop module

      The module Jms MegaMenu (jmsmegamenu) from Joommasters contains a Blind SQL injection vulnerability. This module is for the PrestaShop e-commerce platform and mainly provided with joo masters PrestaShop themes

    • Mar 13, 2023 • #modules • critical (9.8)

      [CVE-2023-27034] Blind SQL injection vulnerability in Jms Blog (jmsblog) PrestaShop module

      The module Jms Blog (jmsblog) from Joommasters contains a Blind SQL injection vulnerability. This module is for the PrestaShop e-commerce platform and mainly provided with joo masters PrestaShop themes

    • Mar 13, 2023 • #core • moderate (5.0)

      [CVE-2023-25170] Possible CSRF token fixation (CWE-352)

      Not clear CSRF tokens upon login…

    • Mar 9, 2023 • #modules • critical (9.8)

      [CVE-2023-25207] Multiple improper neutralization of SQL parameters in DPD France module for PrestaShop

      In the module “DPD France” (dpdfrance) for PrestaShop, a remote attaker can perform a blind SQL injection in affected versions. Release 6.1.3 fixed vulnerabilities.

    « Prev 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 Next »

    Subscribe

    • Friends Of Presta

    Friends Of Presta is a none profit organization that supports the open-source ecommerce platform PrestaShop.