CVE-2026-33673: PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
Impact Multiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates.
Patches Patched on 8.2.5 and 9.1.0
Workarounds None
References None
Other sources
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33673?
CVE-2026-33673 has been classified as a critical security vulnerability due to the potential for stored Cross-Site Scripting attacks.
How do I fix CVE-2026-33673?
To fix CVE-2026-33673, upgrade to PrestaShop version 8.2.5 or later versions starting from 9.1.0.
What types of vulnerabilities are associated with CVE-2026-33673?
CVE-2026-33673 is associated with multiple stored Cross-Site Scripting (XSS) vulnerabilities that can be exploited by attackers.
Who is affected by CVE-2026-33673?
Users running PrestaShop versions prior to 8.2.5 or between 9.0.0-alpha.1 and 9.1.0 are affected by CVE-2026-33673.
What can be the impact of exploiting CVE-2026-33673?
Exploiting CVE-2026-33673 can allow attackers to inject malicious scripts in back-office templates, leading to compromised user data.