CVE-2023-27846: Themevolty Theme Volty CMS Blog

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

SQL injection vulnerability found in PrestaShop themevolty v.4.0.8 and before allow a remote attacker to gain privileges via the tvcmsblog, tvcmsvideotab, tvcmswishlist, tvcmsbrandlist, tvcmscategorychainslider, tvcmscategoryproduct, tvcmscategoryslider, tvcmspaymenticon, tvcmstestimonial components.

Affected products

  • Themevolty Theme Volty CMS Blog: up to and including 4.0.8

Published 2023-10-31. Last modified 2026-06-17.