Stored Cross-Site Scripting in PrestaShop Back-Office Customer Service
CVE-2026-44212
What is CVE-2026-44212?
PrestaShop, an open-source e-commerce platform, is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Customer Service view of its back-office. This issue arises due to the improper handling of user input from the public Contact Us form. An unauthenticated attacker can submit a form containing a malicious email address, resulting in the payload being stored in the application's database. When a back-office employee accesses the affected customer thread, the stored payload executes, potentially allowing the attacker to hijack sessions and gain unauthorized access to the back-office environment. This serious security flaw can lead to a complete compromise of the management interface. The vulnerability has been addressed in versions 8.2.6 and 9.1.1.
Affected Version(s)
PrestaShop < 8.2.6 < 8.2.6
PrestaShop >= 9.0.0-alpha.1, < 9.1.1 < 9.0.0-alpha.1, 9.1.1
