Critical
github
·
GHSA-w9f3-qc75-qgx9
PrestaShop has a stored XSS executable in customer service view
Published May 8, 2026
CVSS 9.3
Impact
This is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view.
An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover.
Patches
Patched in PrestaShop 8.2.6 and 9.1.1.
Workarounds
None.
Resources
- Reported by Savio at Doyensec (
[email protected]) in collaboration with Anthropic Research.
Affected AI Products
anthropic