PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.
We have discovered 1,830 live websites that are affected by CVE-2026-33673.
| Product | |
| Category | Ecommerce |
| Vulnerable Domains | 1,830 live websites (100% of PrestaShop install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 89 versions ( 97% of all versions) |
| 174 websites | |
| 414 websites | |
| 385 websites | |
| 130 websites | |
| 114 websites | |
| 72 websites | |
| 71 websites | |
| 38 websites | |
| 37 websites | |
| 34 websites |
| .com | 798 websites |
| .es | 195 websites |
| .fr | 157 websites |
| .pl | 62 websites |
| .it | 61 websites |
| .cz | 28 websites |
| .de | 25 websites |
| .eu | 23 websites |
| .nl | 22 websites |
| .net | 21 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.de | ***,*** | ||
| *******.de | ***,*** | ||
| ***********.pl | ***,*** | ||
| **************.com | ***,*** | ||
| *******.com | ***,*** | ||
| **********.fr | ***,*** | ||
| **********.com | ***,*** | ||
| ***********.com | ***,*** | ||
| *************.es | ***,*** | ||
| *******.com | ***,*** |
FAQ