VulnWatch VulnWatch
← Back to dashboard
Critical github · GHSA-w9f3-qc75-qgx9

PrestaShop has a stored XSS executable in customer service view

Published May 8, 2026 CVSS 9.3

Impact

This is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view.

An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover.

Patches

Patched in PrestaShop 8.2.6 and 9.1.1.

Workarounds

None.

Resources

  • Reported by Savio at Doyensec ([email protected]) in collaboration with Anthropic Research.

Affected AI Products

anthropic
Get the weekly digest. Every Monday: top AI security stories of the week. Free.