Un module vulnérable reste exploitable même désinstallé, tant que ses fichiers sont présents sur le serveur. Et une mise à jour corrige la faille, mais ne retire pas un skimmer déjà installé.
22 des 25 failles ci-dessous sont signalées comme exploitées activement : si vous utilisez l'un de ces modules dans une version touchée, faites vérifier votre boutique.
| Module | Faille | Touchées | Corrigée | Statut |
|---|---|---|---|---|
| M4 PDF Extensionsm4pdf · PrestaAddons | Injection de code PHP non authentifiéeCVE-2023-50029 · CVSS 10 | <= 3.3.1 | 3.3.2 | ● Exploitée |
| Theme settings (Promokit)pk_themesettings · Promokit.eu | Injection SQL non authentifiéeCVE-2024-36678 · CVSS 9.8 | <= 1.8.8 (versions exactes inconnues) | — | ● Exploitée |
| Search Auto Suggestautosuggest · KnowBand | Injection SQL non authentifiéeCVE-2024-33272 · CVSS 9.8 | < 2.0.0 | 2.0.0 | ● Exploitée |
| Tracking Center - Parcel tracking 80 carriersdeliveryorderautoupdate · Helloshop | Injection SQL non authentifiéeCVE-2024-33266 · CVSS 9.8 | <= 2.8.1 | 2.8.2 | ● Exploitée |
| Product Catalog (CSV, Excel) Importsimpleimportproduct · MyPrestaModules | Téléversement de fichier PHP non authentifiéCVE-2024-25846 · CVSS 10 | <= 6.7.0 | 6.7.1 | ● Exploitée |
| Import/Update Bulk Product from any Csv/Excel File Proba_importer · Buy Addons | Injection SQL non authentifiéeCVE-2024-25843 · CVSS 9.8 | <= 1.1.28 | 1.1.29 | ● Exploitée |
| Newsletter Popup PRO with Voucher/Coupon codenewsletterpop · Active Design | Injection SQL non authentifiéeCVE-2023-47308 · CVSS 9.8 | >= 2.3.1 et <= 2.4.53, >= 2.5.2 et <= 2.6.0 | 2.6.1 | ● Exploitée |
| Advanced configurator for customized productconfigurator · DM Concept | Injection SQL non authentifiéeCVE-2023-43986 · CVSS 9.8 | <= 4.9.3 | 4.9.4 | ● Exploitée |
| One Page Checkout, Social Login & Mailchimpsupercheckout · KnowBand | Téléversement de fichier PHP non authentifiéCVE-2023-45384 · CVSS 10 | <= 6.0.6 | 6.0.7 | ● Exploitée |
| Product Extra Tabs Proextratabspro · MyPresta.eu | Injection SQL non authentifiéeCVE-2023-45386 · CVSS 9.8 | <= 2.2.7 | 2.2.8 | ● Exploitée |
| One Page Checkout, Social Login & Mailchimpsupercheckout · KnowBand | Injection SQL non authentifiéeCVE-2023-44024 · CVSS 9.8 | <= 8.0.3 | 8.0.4 | ● Exploitée |
| Leo Blogleoblog · LeoTheme | Injection SQL non authentifiéeCVE-2023-39639 · CVSS 9.8 | <= 3.1.2 | 3.1.3 | ● Exploitée |
| XML Feeds PROxmlfeeds · Bl Modules | Injection SQL non authentifiéeCVE-2023-39643 · CVSS 9.8 | <= 3.8.2 | 3.9.8 | ● Exploitée |
| Carts Guru - Marketing automation multicanalcartsguru · Carts Guru | Injection SQL non authentifiéeCVE-2023-39642 · CVSS 9.8 | <= 2.4.2 | 2.4.3 | ● Exploitée |
| Static Blocks (PosThemes)posstaticblocks · PosThemes | Injection SQL non authentifiéeCVE-2023-30189 · CVSS 9.8 | <= 1.0 | — | ● Exploitée |
| Cdesignercdesigner · Prestaeg | Téléversement de fichier dangereux non authentifiéCVE-2023-27033 · CVSS 10 | > 3.1.3 et <= 3.2.1 | 3.2.2 | ● Exploitée |
| xipblogxipblog · xpert-idea | Injection SQL non authentifiéeCVE-2023-27847 · CVSS 9.8 | <= 2.0.1 | — | ● Exploitée |
| Jms MegaMenujmsmegamenu · Joommasters | Injection SQL aveugle non authentifiéeCVE-2023-29630 · CVSS 9.8 | Toutes versions (au moins 1.1.x et 2.0.x) | — | ● Exploitée |
| Stripe Payment Pro (SCA-ready)stripejs · NTS | Injection SQL aveugle non authentifiéeCVE-2023-23315 · CVSS 9.8 | < 4.5.5 | 4.5.5 | ● Exploitée |
| PrestaShop (cœur) : cache Smarty MySQLprestashop-core · PrestaShop | Injection SQL chaînée à une exécution de codeCVE-2022-31181 · CVSS 9.8 | >= 1.6.0.10 et < 1.7.8.7 | 1.7.8.7 | ● Exploitée |
| SimpleBlog (Prestahome Blog)ph_simpleblog · Prestahome | Injection SQL non authentifiéeCVE-2021-36748 · CVSS 9.8 | < 1.7.8 | 1.7.8 | ● Exploitée |
| PHPUnit (embarqué dans PrestaShop et des modules officiels)phpunit · PrestaShop | Exécution de code PHP à distance non authentifiéeCVE-2017-9841 · CVSS 9.8 | PrestaShop < 1.7.6.0 ; modules autoupgrade 4.0.0 à 4.10.1, pscartabandonmentpro 2.0.1 à 2.0.10, ps_facetedsearch 2.2.1 à 3.4.1, gamification 2.1.0 à 2.3.2, ps_checkout 1.0.8 à 1.2.9 | — | ● Exploitée |
| Advanced Popup Creatoradvancedpopupcreator · Idnovate | Injection SQL non authentifiéeCVE-2025-69633 · CVSS 9.8 | < 1.2.7 | 1.2.7 | ● À corriger |
| PrestaShop Checkoutps_checkout · PrestaShop | Prise de contrôle de compte clientCVE-2025-61922 · CVSS 9.1 | >= 1.3.0, < 4.4.1 et < 5.0.5 | 4.4.1 / 5.0.5 | ● À corriger |
| Monetico PaiementMoneticoPaiement · Monetico Paiement / EuroInformation | Injection SQL non authentifiéeCVE-2023-45256 · CVSS 9.8 | <= 1.1.0 | 1.1.1 | ● À corriger |
Source : avis de sécurité Friends Of Presta, vérifiés le 24 septembre 2026. Cette liste est une sélection : consultez la source pour l'ensemble des avis.