{"id":"CVE-2023-39527","aliases":["GHSA-xw2r-f8xv-c8xp"],"url":"https://o3.security/vulnerability/CVE-2023-39527","summary":"PrestaShop XSS vulnerability through Validate::isCleanHTML method","details":"PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to cross-site scripting through the `isCleanHTML` method. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.","published":"2023-08-07T20:32:45.203Z","modified":"2026-08-08T03:47:45.951860960Z","cvss":{"score":8.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"prestashop/prestashop","fixedVersion":"8.1.1"},{"ecosystem":"Packagist","name":"prestashop/prestashop","fixedVersion":"8.0.5"},{"ecosystem":"Packagist","name":"prestashop/prestashop","fixedVersion":"1.7.8.10"}],"fix":{"url":"https://github.com/PrestaShop/PrestaShop/commit/afc14f8eaa058b3e6a20ac43e033ee2656fb88b4","label":"PrestaShop/PrestaShop@afc14f8"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/39xxx/CVE-2023-39527.json"},{"type":"ADVISORY","url":"https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-xw2r-f8xv-c8xp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-39527"},{"type":"FIX","url":"https://github.com/PrestaShop/PrestaShop/commit/afc14f8eaa058b3e6a20ac43e033ee2656fb88b4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:45.951860960Z"}}