Myprestamodules

    Dashboard / Vendors

    Products: 8
    Vulnerabilities: 12
    Known Exploited: 0
    7
    Critical Level Threats
    5
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-28396

    An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component.

    Last Modified: Jun 17, 2025
    Published: Mar 20, 2024

    CVE-2024-25847

    SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods.

    Last Modified: May 05, 2025
    Published: Mar 03, 2024

    CVE-2024-25846

    In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.

    Last Modified: Feb 18, 2026
    Published: Feb 27, 2024

    CVE-2023-46354

    In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer/ps_address tables such as name / surname / email / phone number / full postal address.

    Last Modified: Nov 21, 2024
    Published: Dec 06, 2023

    CVE-2023-46349

    In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpdateModel::getExportIds()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

    Last Modified: Nov 26, 2024
    Published: Nov 27, 2023
    Items Per Page
    Myprestamodules Vulnerabilities & Security CVEs | CVE-DB