# CVE-2026-33674

## Summary

- **CVE ID:** CVE-2026-33674
- **Severity:** LOW
- **CVSS Score:** 2 (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N)
- **CWE:** CWE-1173
- **Published:** Mar 26, 2026
- **Last Modified:** Mar 30, 2026

## Description

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.

## Affected Products

- PrestaShop — PrestaShop (< 8.2.5)
- PrestaShop — PrestaShop (>= 9.0.0-alpha.1, < 9.1.0)

## References

- [CNA](https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-283w-xf3q-788v)
- [CNA](https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.5)
- [CNA](https://github.com/PrestaShop/PrestaShop/releases/tag/9.1.0)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.24%
- **EPSS Percentile:** 14.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._