● Veille sécurité PrestaShop

Failles PrestaShop : les modules qui font voler des cartes

La plupart des boutiques PrestaShop piratées le sont par un module vulnérable. Voici les failles les plus dangereuses, vérifiées une à une dans les avis de sécurité publics.

06 52 86 53 11

Mis à jour le 24 septembre 2026

Un module vulnérable reste exploitable même désinstallé, tant que ses fichiers sont présents sur le serveur. Et une mise à jour corrige la faille, mais ne retire pas un skimmer déjà installé.

22 des 25 failles ci-dessous sont signalées comme exploitées activement : si vous utilisez l'un de ces modules dans une version touchée, faites vérifier votre boutique.

ModuleFailleTouchéesCorrigéeStatut
M4 PDF Extensionsm4pdf · PrestaAddonsInjection de code PHP non authentifiéeCVE-2023-50029 · CVSS 10<= 3.3.13.3.2● Exploitée
Theme settings (Promokit)pk_themesettings · Promokit.euInjection SQL non authentifiéeCVE-2024-36678 · CVSS 9.8<= 1.8.8 (versions exactes inconnues)—● Exploitée
Search Auto Suggestautosuggest · KnowBandInjection SQL non authentifiéeCVE-2024-33272 · CVSS 9.8< 2.0.02.0.0● Exploitée
Tracking Center - Parcel tracking 80 carriersdeliveryorderautoupdate · HelloshopInjection SQL non authentifiéeCVE-2024-33266 · CVSS 9.8<= 2.8.12.8.2● Exploitée
Product Catalog (CSV, Excel) Importsimpleimportproduct · MyPrestaModulesTéléversement de fichier PHP non authentifiéCVE-2024-25846 · CVSS 10<= 6.7.06.7.1● Exploitée
Import/Update Bulk Product from any Csv/Excel File Proba_importer · Buy AddonsInjection SQL non authentifiéeCVE-2024-25843 · CVSS 9.8<= 1.1.281.1.29● Exploitée
Newsletter Popup PRO with Voucher/Coupon codenewsletterpop · Active DesignInjection SQL non authentifiéeCVE-2023-47308 · CVSS 9.8>= 2.3.1 et <= 2.4.53, >= 2.5.2 et <= 2.6.02.6.1● Exploitée
Advanced configurator for customized productconfigurator · DM ConceptInjection SQL non authentifiéeCVE-2023-43986 · CVSS 9.8<= 4.9.34.9.4● Exploitée
One Page Checkout, Social Login & Mailchimpsupercheckout · KnowBandTéléversement de fichier PHP non authentifiéCVE-2023-45384 · CVSS 10<= 6.0.66.0.7● Exploitée
Product Extra Tabs Proextratabspro · MyPresta.euInjection SQL non authentifiéeCVE-2023-45386 · CVSS 9.8<= 2.2.72.2.8● Exploitée
One Page Checkout, Social Login & Mailchimpsupercheckout · KnowBandInjection SQL non authentifiéeCVE-2023-44024 · CVSS 9.8<= 8.0.38.0.4● Exploitée
Leo Blogleoblog · LeoThemeInjection SQL non authentifiéeCVE-2023-39639 · CVSS 9.8<= 3.1.23.1.3● Exploitée
XML Feeds PROxmlfeeds · Bl ModulesInjection SQL non authentifiéeCVE-2023-39643 · CVSS 9.8<= 3.8.23.9.8● Exploitée
Carts Guru - Marketing automation multicanalcartsguru · Carts GuruInjection SQL non authentifiéeCVE-2023-39642 · CVSS 9.8<= 2.4.22.4.3● Exploitée
Static Blocks (PosThemes)posstaticblocks · PosThemesInjection SQL non authentifiéeCVE-2023-30189 · CVSS 9.8<= 1.0—● Exploitée
Cdesignercdesigner · PrestaegTéléversement de fichier dangereux non authentifiéCVE-2023-27033 · CVSS 10> 3.1.3 et <= 3.2.13.2.2● Exploitée
xipblogxipblog · xpert-ideaInjection SQL non authentifiéeCVE-2023-27847 · CVSS 9.8<= 2.0.1—● Exploitée
Jms MegaMenujmsmegamenu · JoommastersInjection SQL aveugle non authentifiéeCVE-2023-29630 · CVSS 9.8Toutes versions (au moins 1.1.x et 2.0.x)—● Exploitée
Stripe Payment Pro (SCA-ready)stripejs · NTSInjection SQL aveugle non authentifiéeCVE-2023-23315 · CVSS 9.8< 4.5.54.5.5● Exploitée
PrestaShop (cœur) : cache Smarty MySQLprestashop-core · PrestaShopInjection SQL chaînée à une exécution de codeCVE-2022-31181 · CVSS 9.8>= 1.6.0.10 et < 1.7.8.71.7.8.7● Exploitée
SimpleBlog (Prestahome Blog)ph_simpleblog · PrestahomeInjection SQL non authentifiéeCVE-2021-36748 · CVSS 9.8< 1.7.81.7.8● Exploitée
PHPUnit (embarqué dans PrestaShop et des modules officiels)phpunit · PrestaShopExécution de code PHP à distance non authentifiéeCVE-2017-9841 · CVSS 9.8PrestaShop < 1.7.6.0 ; modules autoupgrade 4.0.0 à 4.10.1, pscartabandonmentpro 2.0.1 à 2.0.10, ps_facetedsearch 2.2.1 à 3.4.1, gamification 2.1.0 à 2.3.2, ps_checkout 1.0.8 à 1.2.9—● Exploitée
Advanced Popup Creatoradvancedpopupcreator · IdnovateInjection SQL non authentifiéeCVE-2025-69633 · CVSS 9.8< 1.2.71.2.7● À corriger
PrestaShop Checkoutps_checkout · PrestaShopPrise de contrôle de compte clientCVE-2025-61922 · CVSS 9.1>= 1.3.0, < 4.4.1 et < 5.0.54.4.1 / 5.0.5● À corriger
Monetico PaiementMoneticoPaiement · Monetico Paiement / EuroInformationInjection SQL non authentifiéeCVE-2023-45256 · CVSS 9.8<= 1.1.01.1.1● À corriger

Source : avis de sécurité Friends Of Presta, vérifiés le 24 septembre 2026. Cette liste est une sélection : consultez la source pour l'ensemble des avis.

● Ligne d'urgence ouverte

Chaque heure compte. Appelez maintenant.

📞 06 52 86 53 11

Perte :0,00 €

Demande d'intervention

📞 Appeler le 06 52 86 53 11

ou laissez vos coordonnées :