CVE-2020-15178: Prestashop Contactform
Critical severity, CVSS 9.3. EPSS: 1.2% chance of exploitation in the next 30 days.
In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript while using the contact form. The `message` field was incorrectly unescaped, possibly allowing attackers to execute arbitrary JavaScript in a victim's browser.
Affected products
- Prestashop Contactform: before 4.3.0 (fixed in 4.3.0)
Published 2020-09-15. Last modified 2026-06-17.