CVE-2023-45386: Mypresta Product Extra Tabs Pro
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
In the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via `extratabspro::searchcategory()`, `extratabspro::searchproduct()` and `extratabspro::searchmanufacturer().'
Affected products
- Mypresta Product Extra Tabs Pro: before 2.2.8 (fixed in 2.2.8)
Published 2023-10-17. Last modified 2026-06-17.