Prestalife
Prestalife Product Designer: vulnerabilidades y CVE
Prestalife Product Designer tiene 6 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-39726 | Alta (7.1) | 0.24% | — | 6 oct 2026 | Unauthenticated Cross Site Scripting (XSS) in Lumise Product Designer <= 2.1.1 versions. |
| CVE-2024-9111 | Media (6.4) | 0.53% | — | 21 nov 2024 | The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.36 due to insufficient input sanitization and output escaping. This… |
| CVE-2024-3608 | Media (5.3) | 0.56% | — | 9 jul 2024 | The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including,… |
| CVE-2024-26469 | Alta (8.1) | 0.31% | — | 3 mar 2024 | Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to cause a denial of service (DoS) and escalate… |
| CVE-2024-24302 | Crítica (9.8) | 0.93% | — | 3 mar 2024 | An issue was discovered in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive… |
| CVE-2024-24307 | Alta (7.5) | 0.72% | — | 3 mar 2024 | Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remote attacker to escalate privileges and obtain sensitive information via the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.