CVE-2026-33673

PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.


We have discovered 1,830 live websites that are affected by CVE-2026-33673.

Run a Free Instant Scan




Affected Software

Product  PrestaShop
Category Ecommerce
Vulnerable Domains1,830 live websites (100% of PrestaShop install base)
Vulnerable Versions
  • from 0 through 8.2.5
  • from 9 through 9.1
Vulnerable Versions Count89 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Mar 26, 2026
  • Updated - Mar 27, 2026

Website Distribution by Country

Number of websites using CVE-2026-33673
United States174 websites



Spain414 websites
France385 websites
Iran130 websites
Germany114 websites
Italy72 websites
Poland71 websites
Czech Republic38 websites
Chile37 websites
Norway34 websites

Website Distribution by TLD

Number of websites using CVE-2026-33673
.com798 websites
.es195 websites
.fr157 websites
.pl62 websites
.it61 websites
.cz28 websites
.de25 websites
.eu23 websites
.nl22 websites
.net21 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-33673

Top websites that are affected by CVE-2026-33673. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.de Germany***,***
*******.de Germany***,***
***********.pl Poland***,***
**************.com Spain***,***
*******.com United States***,***
**********.fr France***,***
**********.com France***,***
***********.com France***,***
*************.es Spain***,***
*******.com France***,***
See full domain list

FAQ

CVE-2026-33673 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in PrestaShop
A total of 1,830 websites have been identified as vulnerable to CVE-2026-33673, based on global website indexing conducted by WebTechSurvey.
The PrestaShop is affected by the CVE-2026-33673 vulnerability.
PrestaShop versions up to 9.1 are vulnerable to CVE-2026-33673.
CVE-2026-33673 is resolved in version 9.1 of PrestaShop.