CVE-2024-33272: Prestashop

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

SQL injection vulnerability in KnowBand for PrestaShop autosuggest before 2.0.0 allows an attacker to run arbitrary SQL commands via the AutosuggestSearchModuleFrontController::initContent(), and AutosuggestSearchModuleFrontController::getKbProducts() components.

Affected products

  • Prestashop Prestashop: before 2.0.0 (fixed in 2.0.0)

Published 2024-04-29. Last modified 2026-06-17.