CVE-2020-15161: Prestashop
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8
Affected products
- Prestashop Prestashop: from 1.6.0.4, before 1.7.6.8 (fixed in 1.7.6.8)
Published 2020-09-24. Last modified 2026-06-17.