CVE-2024-21627: Prestashop
Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.
PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` method. Some modules using the `isCleanHTML` method could be vulnerable to cross-site scripting. Versions 8.1.3 and 1.7.8.11 contain a patch for this issue. The best workaround is to use the `HTMLPurifier` library to sanitize html input coming from users. The library is already available as a dependency in the PrestaShop project. Beware though that in legacy object models, fields of `HTML` type will call `isCleanHTML`.
Affected products
- Prestashop Prestashop: before 1.7.8.11 (fixed in 1.7.8.11); from 8.0.0, before 8.1.3 (fixed in 8.1.3)
Published 2024-01-02. Last modified 2026-06-17.