Prestalife
Prestalife Product Designer: vulnerabilities and CVEs
Prestalife Product Designer has 6 published vulnerabilities, 1 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months1
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39726 | High (7.1) | 0.24% | — | Oct 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Lumise Product Designer <= 2.1.1 versions. |
| CVE-2024-9111 | Medium (6.4) | 0.53% | — | Nov 21, 2024 | The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.36 due to insufficient input sanitization and output escaping. This… |
| CVE-2024-3608 | Medium (5.3) | 0.56% | — | Jul 9, 2024 | The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including,… |
| CVE-2024-26469 | High (8.1) | 0.31% | — | Mar 3, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to cause a denial of service (DoS) and escalate… |
| CVE-2024-24302 | Critical (9.8) | 0.93% | — | Mar 3, 2024 | An issue was discovered in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive… |
| CVE-2024-24307 | High (7.5) | 0.72% | — | Mar 3, 2024 | Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remote attacker to escalate privileges and obtain sensitive information via the… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.