CVE-2023-39527: Prestashop

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to cross-site scripting through the `isCleanHTML` method. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.

Affected products

  • Prestashop Prestashop: before 1.7.8.10 (fixed in 1.7.8.10); from 8.0.0, before 8.0.5 (fixed in 8.0.5); version 8.1.0 only

Published 2023-08-07. Last modified 2026-06-17.