CVE-2026-44212 - Vulnerability Analysis
CriticalCVSS: 9.3Last Updated: May 14, 2026
PrestaShop - Stored XSS
Published: May 14, 2026Updated: May 14, 2026Remote Exploitable
Overview
PrestaShop < 8.2.6 and < 9.1.1 contains a stored XSS caused by improper sanitization of email input in the back-office Customer Service view, letting unauthenticated attackers hijack sessions and take over back-office, exploit requires back-office employee to open malicious customer thread.
Severity & Score
Severity: Critical
CVSS Score: 9.3
Impact
Unauthenticated attackers can hijack back-office sessions and fully take over the back-office.
Mitigation
Update to versions 8.2.6 or 9.1.1 or later.
Related Resources
Details
- CVE ID
- CVE-2026-44212
- Severity
- Critical
- CVSS Score
- 9.3
- Type
- stored_xss
- Status
- new
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N