Vendor
Unauthenticated PHP Object Injection in PrestaShop ps_facetedsearch Leads to RCE
1 rule 3 TTPsAn unauthenticated PHP Object Injection vulnerability, tracked as CVE-2026-54159, affects the PrestaShop ps_facetedsearch module versions 3.0.0 through 4.0.3, allowing attackers to craft malicious serialized PHP objects in URL parameters that, upon deserialization, result in arbitrary file writes and remote code execution on the server.
PrestaShop Stored XSS in Customer Service View Allows Back-Office Takeover
2 rules 1 TTP 1 IOCA stored cross-site scripting (XSS) vulnerability exists in PrestaShop's back-office customer service view, where an unauthenticated attacker can submit a malicious email address via the Contact Us form, leading to session hijacking and full back-office takeover when an employee opens the affected customer thread; patched in PrestaShop 8.2.6 and 9.1.1.
PrestaShop Stored XSS Vulnerability via Unprotected Template Variables
3 rules 1 TTPMultiple stored XSS vulnerabilities exist in PrestaShop, where an attacker with database access can exploit unprotected variables in back-office templates to execute malicious scripts in a user's browser.