PrestaShop has a stored XSS executable in customer service view
Critical severity
GitHub Reviewed
Published
May 4, 2026
in
PrestaShop/PrestaShop
•
Updated May 8, 2026
Package
Affected versions
< 8.2.6
>= 9.0.0, < 9.1.1
Patched versions
8.2.6
9.1.1
Description
Published to the GitHub Advisory Database
May 8, 2026
Reviewed
May 8, 2026
Last updated
May 8, 2026
Impact
This is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view.
An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover.
Patches
Patched in PrestaShop 8.2.6 and 9.1.1.
Workarounds
None.
Resources
anthropic@doyensec.com) in collaboration with Anthropic Research.References