CVE-2026-44212
Impact
This is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view.
An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover.
Patches
Patched in PrestaShop 8.2.6 and 9.1.1.
Workarounds
None.
Resources
- Reported by Savio at Doyensec (
anthropic@doyensec.com) in collaboration with Anthropic Research.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-w9f3-qc75-qgx9, https://github.com/PrestaShop/PrestaShop
