Vulnerabilities (CVE)

Filtered by vendor Common-services Subscribe
Filtered by product So Flexibilite
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25841 1 Common-services 1 So Flexibilite 2025-05-23 N/A 5.9 MEDIUM
In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection.
CVE-2024-25844 1 Common-services 1 So Flexibilite 2025-05-23 N/A 7.5 HIGH
An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file.