/
    Zpět na blog
    Security

    Critical vulnerabilities in PrestaShop


    Critical vulnerabilities in PrestaShop#### The PrestaShop project, which has powered more than 300,000 web stores worldwide since 2007, recently issued a security alert revealing two critical vulnerabilities.

    image

    The first vulnerability, tracked as CVE-2024–34717, allows unauthorised individuals to download other customers invoices. This data breach could result in the exposure of sensitive financial and customer information.

    The second vulnerability, identified as CVE-2024–34716, is a cross-site scripting (XSS) attack that allows hackers to inject malicious code into a contact form. This code can then be executed when viewed by an administrator, giving the attacker access to the entire backend of the store and sensitive information.

    PrestaShop has released version 8.1.6, which includes fixes for both issues. We strongly recommend that all PrestaShop users upgrade to this latest version immediately to protect their stores and customer data.

    © 2026 Patrik Žák. Všechna práva vyhrazena.