Skip to content

PrestaShop

Productivity & Wikis

Open source e-commerce web application written in PHP

PHP Latest 9.1.3 · 13d ago Security brief →

Features

  • PHP‑based open‑source shopping cart platform
  • Highly customizable storefronts and back offices
  • Support for major payment services and multi‑language/localization

Security Response History

1 CVE
CVE Severity Disclosed Patched (this tool) vs Ecosystem Median
CVE-2020-11023 KEV medium
CVSS 6.9
2025-01-23 2026-02-03 1y / median 1y 1mo

Recent releases

View all 8 releases →
No immediate action
9.1.2 Mixed

--skip-overrides + Symfony update + ValueObject improvements

patches CVE-2020-11023
Open
8.2.6 Security relevant
Security fixes
  • Prevent XSS exploitation via unprotected variables in customer threads (GHSA-w9f3-qc75-qgx9)
Full changelog
  • Back Office
    • Improvement:
      • GHSA-w9f3-qc75-qgx9 Prevent xss exploitation via unprotected variables in customer threads (found by Savio from Doyensec in collaboration with Anthropic Research)

Full Changelog: https://github.com/PrestaShop/PrestaShop/compare/8.2.5...8.2.6

9.1.1 Security relevant
Security fixes
  • Prevent XSS exploitation via unprotected variables in customer threads (GHSA-w9f3-qc75-qgx9)
Full changelog
  • Back Office
    • Improvement:
      • GHSA-w9f3-qc75-qgx9 Prevent xss exploitation via unprotected variables in customer threads (found by Savio from Doyensec in collaboration with Anthropic Research)

Full Changelog: https://github.com/PrestaShop/PrestaShop/compare/9.1.0...9.1.1

9.1.0 New feature
Breaking changes
  • Default theme changed to Hummingbird 2.0
Notable features
  • Hummingbird 2.0
  • Multi-carrier shipping
  • Discount redesign
8.2.5 Security relevant
Security fixes
  • GHSA-35pf-37c6-jxjv - XSS in templates
  • GHSA-283w-xf3q-788v - Validation framework

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
9,093
Forks
5,044
Languages
PHP TypeScript Gherkin

Install & Platforms

Install via
docker

Community & Support

Beta — feedback welcome: [email protected]