CVE-2018-13784: Prestashop
Critical severity, CVSS 9.1. EPSS: 16.5% chance of exploitation in the next 30 days.
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.
Affected products
- Prestashop Prestashop: before 1.6.1.20 (fixed in 1.6.1.20); from 1.7.0.0, before 1.7.3.4 (fixed in 1.7.3.4)
Published 2018-07-09. Last modified 2026-06-17.