CVE-2020-15080: Prestashop

Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.

In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. The problem is fixed in version 1.7.6.6 A possible workaround is to make sure `composer.json` and `docker-compose.yml` are not accessible on your server.

Affected products

  • Prestashop Prestashop: after 1.7.4.0, before 1.7.6.6 (fixed in 1.7.6.6)

Published 2020-07-02. Last modified 2026-06-17.