CVE-2025-25691: Prestashop
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.
Affected products
- Prestashop Prestashop: version 8.2.0 only
Published 2025-07-30. Last modified 2026-07-05.