Xpert-idea

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 1
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-38725

    xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input is stored in the database without HTML sanitization and rendered in Smarty templates without output escaping, resulting in Stored Cross-Site Scripting (XSS). When an administrator reviews comments in the back office, the payload executes with admin-level session context, leading to full store compromise.

    Last Modified: Sep 01, 2026
    Published: Aug 28, 2026
    Items Per Page
    Xpert-Idea Vulnerabilities & Security CVEs | CVE-DB