CVE-2026-25597: PrestaShop has a time based enumeration in FO login form
Impact A time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times.
Patches 8.2.4 and 9.0.3
Workarounds none
References Found by Lam Yiu Tung
Other sources
PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. This vulnerability is fixed in 8.2.4 and 9.0.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25597?
CVE-2026-25597 is a medium-severity vulnerability due to its potential for user enumeration through time-based responses.
How do I fix CVE-2026-25597?
To fix CVE-2026-25597, upgrade PrestaShop to version 8.2.4 or 9.0.3 or later.
What does CVE-2026-25597 exploit?
CVE-2026-25597 exploits the user authentication functionality in the PrestaShop login form.
Which versions of PrestaShop are affected by CVE-2026-25597?
CVE-2026-25597 affects PrestaShop versions prior to 8.2.4 and between versions 9.0.0-alpha.1 and 9.0.3.
How can CVE-2026-25597 impact my PrestaShop site?
CVE-2026-25597 can allow attackers to determine the existence of customer accounts, potentially leading to further exploitation.