CERT Polska has received a report about 2 SQL Injection vulnerabilities (CVE-2026-7848 and CVE-2026-15600) found in Alior Bank "raty" module for PrestaShop.
Incorrect access control in PrestaShop Mon, 09/07/2026 - 13:19 Aviso Affected Resources PrestaShop, versions prior to 9.1.5 and 8.2.8, depending on the branch. Description INCIBE has coordinated the publication of a medium-severity vulnerability affecting PrestaShop, a free and open-source content management system designed to build e-commerce online shops from scratch. The vulnerability was discovered by Pedro Gabaldón Juliá.This vulnerability has been assigned the following code, CVSS v4.0…
Incorrect neutralisation in the PrestaShop firmware Mon, 07/13/2026 - 09:58 Aviso Affected Resources PrestaShop V8.2.1 Description INCIBE has coordinated the publication of a medium-severity vulnerability affecting the firmware of PrestaShop, a content management system for creating and managing online shops.This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability typeCVE-2026-14846: CVSS v4.0: 4.5 | CVSS AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L…