CVE-2012-20001: Prestashop

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.

Affected products

  • Prestashop Prestashop: before 1.5.2 (fixed in 1.5.2)

Published 2021-12-21. Last modified 2026-06-16.