CVE-2023-34577: Planned Popup Project Planned Popup

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

SQL injection vulnerability in Prestashop opartplannedpopup 1.4.11 and earlier allows remote attackers to run arbitrary SQL commands via OpartPlannedPopupModuleFrontController::prepareHook() method.

Affected products

Published 2023-09-21. Last modified 2026-06-17.