CVE-2026-14846

In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation of the ‘Alias’ parameter in the ‘Update your address’ function. This flaw allows an attacker to inject malicious expressions that are executed when the information is exported using the ‘Get my data in CSV’ tool. Successful exploitation of this vulnerability could facilitate unauthorised access to the victim’s personal data.

Scoring

Severity
MEDIUM
CVSS base score
4.5
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:H
EPSS probability
0.43%
CWE
CWE-1236
Published
2026-07-13
Last modified
2026-07-13

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs