CVE-2026-44212Patch

MEDIUMCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. This vulnerability is fixed in 8.2.6 and 9.1.1.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-12); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-08: 1Mentions · 2026-05-12: 2Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Active Exploitation · 2026-05-08: 1Patch / Workaround · 2026-05-12: 2Technical Details · 2026-05-08: 1Technical Details · 2026-05-12: 2Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 105-0805-1205-1405-15
Signal classification3 categories
Patch
240.0%
Disclosure
240.0%
Active Exploitation
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-081
Active Exploitation1
2026-05-122
Patch2
2026-05-141
Disclosure1
2026-05-151
Disclosure1
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Patch

    Urgent: PrestaShop patches a 9.3 severity XSS flaw (CVE-2026-44212) that allows unauthenticated attackers to hijack your store's back office. Update now! #PrestaShop #EcommerceSecurity #CyberSecurity #InfoSec #PatchNow #WebSecurity #VulnerabilityAlert #CVE https://securityonline.info/prestashop-critical-xss-vulnerability-cve-2026-44212-patch/ https://t.co/0CdQXg3ABz

    Post summary

    PrestaShop has issued a patch for the critical XSS vulnerability CVE‑2026‑44212, which carries a 9.3 severity score and lets unauthenticated attackers hijack the back office. Users are urged to update immediately.

    02011263
    11.9K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    PrestaShopの問い合わせフォームに重大(Critical)な脆弱性。CVE-2026-44212はCVSSスコア9.3のクロスサイトスクリプティング。メールアドレス欄が脆弱。修正版提供あり。 https://securityonline.info/prestashop-critical-xss-vulnerability-cve-2026-44212-patch/

    Post summary

    PrestaShop's contact form contains a critical cross‑site scripting flaw (CVE‑2026‑44212, CVSS 9.3) affecting the email field, but a patch has already been released.

    00020786
    7.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44212 Stored Cross-Site Scripting in PrestaShop Back-Office Customer Service Below 8.2.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44212

    Post summary

    The entry reports a stored XSS flaw (CVE-2026-44212) affecting PrestaShop Back‑Office Customer Service versions under 8.2.6, with no PoC, exploit, or patch details provided.

    0000044
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44212 PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-o… https://www.cve.org/CVERecord?id=CVE-2026-44212

    Post summary

    The passage discloses a stored XSS vulnerability in PrestaShop versions prior to 8.2.6 and 9.1.1, referencing the official CVE record, but does not mention PoC, active exploitation, or remediation.

    00000146
    57.5K followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Active Exploitation

    Today (Fri, May 8): 1 KEV, 6 critical CVEs. LiteLLM SQLi (KEV) earlier. Long tail: - Open WebUI: 7 advisories, LDAP empty-password bypass (CVE-2026-44551, 9.1) - Electerm SSH client: 4 RCE-class bugs (CVE-2026-43940, 9.8) - PrestaShop stored XSS (CVE-2026-44212, 9.3)

    Post summary

    The tweet cites six critical CVEs, explicitly noting one as a Known Exploited Vulnerability (LiteLLM SQLi), while providing CVE identifiers and CVSS scores but no exploit code or patches.

    0000077
    34 followersView on X

Explore more