
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33674 is a vulnerability in PrestaShop, an open source e-commerce web application, caused by improper use of the validation framework (CWE-1173). It affects all versions prior to 8.2.5 and versions 9.0.0-alpha.1 through 9.1.0 (exclusive). The vulnerability was published on March 23, 2026, and patched versions were released the same day. The GitHub Advisory Database assigns it a CVSS v3.1 score of 2.0 (Low) with vector CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N, while Feedly's estimate places it as High (5.3) based on a different vector assessment (GitHub Advisory, PrestaShop Advisory).
The vulnerability is classified under CWE-1173 (Improper Use of Validation Framework), meaning PrestaShop's codebase fails to correctly apply or leverage its available input validation mechanisms in certain code paths. According to the GitHub advisory, exploitation requires high attack complexity, high privileges, and user interaction, significantly limiting the practical attack surface. No specific technical write-ups, PoC code, or detailed exploitation mechanics have been publicly disclosed beyond the advisory description (GitHub Advisory, PrestaShop Advisory).
Successful exploitation of this vulnerability results in a limited integrity impact — specifically, low-level unauthorized data modification — with no confidentiality or availability impact. Given the high privilege and user interaction requirements, the practical risk is constrained to scenarios where an attacker already holds elevated access and can induce user interaction. There is no evidence of data exfiltration risk or lateral movement potential associated with this vulnerability (GitHub Advisory).
There is no known public exploit code, active in-the-wild exploitation, or threat actor attribution associated with CVE-2026-33674. The EPSS score is approximately 0.028% (9th percentile), indicating a very low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
PrestaShop has released patched versions 8.2.5 and 9.1.0, both published on March 23, 2026, which address this vulnerability. Users running versions below 8.2.5 or between 9.0.0-alpha.1 and 9.1.0 should upgrade immediately. No configuration-based workarounds are available according to the official advisory (PrestaShop 8.2.5 Release, PrestaShop 9.1.0 Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."