Stored Cross-Site Scripting in PrestaShop Back-Office Customer Service
CVE-2026-44212

9.3CRITICAL

Key Information:

Vendor

Prestashop

Vendor
CVE Published:
14 May 2026

What is CVE-2026-44212?

PrestaShop, an open-source e-commerce platform, is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Customer Service view of its back-office. This issue arises due to the improper handling of user input from the public Contact Us form. An unauthenticated attacker can submit a form containing a malicious email address, resulting in the payload being stored in the application's database. When a back-office employee accesses the affected customer thread, the stored payload executes, potentially allowing the attacker to hijack sessions and gain unauthorized access to the back-office environment. This serious security flaw can lead to a complete compromise of the management interface. The vulnerability has been addressed in versions 8.2.6 and 9.1.1.

Affected Version(s)

PrestaShop < 8.2.6 < 8.2.6

PrestaShop >= 9.0.0-alpha.1, < 9.1.1 < 9.0.0-alpha.1, 9.1.1

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.