CVE-2026-33674
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.
Scoring
- Severity
- LOW
- CVSS base score
- 2
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N
- EPSS probability
- 0.24%
- CWE
- CWE-1173
- Published
- 2026-03-26
- Last modified
- 2026-03-30
Affected products
- PrestaShop PrestaShop
- PrestaShop PrestaShop
Weakness type
Related vulnerabilities
- CVE-2024-58360 — stoatchat before 0.7.8 Unrestricted Account Creation
- CVE-2025-48490 — Laravel Rest Api has a Search Validation Bypass
- CVE-2025-3940 — Improper Use of Validation Framework
- CVE-2023-30949 — CVE-2023-30949
- CVE-2022-1414 — 3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An...
- CVE-2020-1640 — Junos OS: Receipt of certain genuine BGP packets from any BGP Speaker causes RPD to crash.