CVE-2026-14846 MEDIUM

CVE-2026-14846: Incorrect neutralisation in the PrestaShop firmware

Vendor Prestashop
Product The firmware
Weakness CWE-1236
Published July 13, 2026
Last update July 13, 2026

CVSS base score

4.5/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:H

What the vulnerability does

01Description

In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation of the ‘Alias’ parameter in the ‘Update your address’ function. This flaw allows an attacker to inject malicious expressions that are executed when the information is exported using the ‘Get my data in CSV’ tool. Successful exploitation of this vulnerability could facilitate unauthorised access to the victim’s personal data.

Key dates

02Disclosure timeline

July 13, 2026 CVE published

Related vulnerabilities

04Related CVE