logo

Critical PrestaShop Flaw Allows Hijacking via “Contact Us” Form

ID: 45bc1c80-6eb0-5fe9-8290-7a2bd8474f92

STIX ID: report--45bc1c80-6eb0-5fe9-8290-7a2bd8474f92

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Ddos

...
...

PrestaShop disclosed a critical stored XSS (CVE-2026-44212, CVSS 9.3) in its "Contact Us" form where an unauthenticated attacker can submit a malicious payload that is stored and later executed in an administrator's browser, enabling full back-office takeover; administrators are urged to apply the vendor's patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.