Stored XSS Vulnerability in PrestaShop Affecting Versions Prior to 8.2.5 and 9.1.0
CVE-2026-33673
7.7HIGH
What is CVE-2026-33673?
PrestaShop, a widely used open-source e-commerce web application, is susceptible to stored Cross-Site Scripting (XSS) vulnerabilities in its back-office interface. Specifically, any version prior to 8.2.5 and 9.1.0 is at risk. The vulnerability allows attackers with limited access to inject harmful data into the database, exploiting unprotected variables within back-office templates. While upgrades to versions 8.2.5 and 9.1.0 address this issue, no known workarounds exist for these vulnerable versions.
Affected Version(s)
PrestaShop >= 9.0.0-alpha.1, < 9.1.0 < 9.0.0-alpha.1, 9.1.0
PrestaShop < 8.2.5 < 8.2.5
