CVE-2013-4791: Prestashop

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.

Affected products

  • Prestashop Prestashop: before 1.4.11 (fixed in 1.4.11)

Published 2020-02-14. Last modified 2026-06-16.