PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
Package
Affected versions
>= 9.0.0-alpha.1, < 9.1.0
< 8.2.5
Patched versions
9.1.0
8.2.5
Description
Published to the GitHub Advisory Database
Mar 25, 2026
Reviewed
Mar 25, 2026
Impact
Multiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates.
Patches
Patched on 8.2.5 and 9.1.0
Workarounds
None
References
None
References