CVE-2023-27032: Idnovate Popup Module (on Entering, Exit Popup, Add Product) And Newsletter

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups().

Affected products

  • Idnovate Popup Module (on Entering, Exit Popup, Add Product) And Newsletter: from 1.1.21, before 1.1.25 (fixed in 1.1.25)

Published 2023-04-12. Last modified 2026-06-17.