CVE-2025-25691: Prestashop

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

Affected products

Published 2025-07-30. Last modified 2026-07-05.