{"id":"CVE-2026-44212","aliases":["GHSA-w9f3-qc75-qgx9"],"url":"https://o3.security/vulnerability/CVE-2026-44212","summary":"PrestaShop: Stored XSS executable in customer service view","details":"### Impact\n\nThis is a **stored Cross-site Scripting (XSS)** vulnerability in the PrestaShop back-office Customer Service view.\n\nAn unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover.\n\n### Patches\n\nPatched in PrestaShop 8.2.6 and 9.1.1.\n\n### Workarounds\n\nNone.\n\n### Resources\n\n- Reported by Savio at Doyensec (`anthropic@doyensec.com`) in collaboration with Anthropic Research.","published":"2026-05-14T20:44:08.152Z","modified":"2026-08-12T03:51:18.371460731Z","cvss":{"score":9.3,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"},"epss":{"score":0.00331,"percentile":0.25469,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"prestashop/prestashop","fixedVersion":"8.2.6"},{"ecosystem":"Packagist","name":"prestashop/prestashop","fixedVersion":"9.1.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44212.json"},{"type":"ADVISORY","url":"https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-w9f3-qc75-qgx9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44212"},{"type":"PACKAGE","url":"https://github.com/PrestaShop/PrestaShop"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:18.371460731Z"}}