infosec.[verified]@inf0seccDisclosure
The post announces CVE-2026-54159, detailing a PHP Object Injection flaw that can lead to remote code execution, and recommends upgrading to v4.0.4 to mitigate the risk.
Upwind Security MDR[verified]@UpwindMDRDisclosure
A critical PrestaShop ‘ps_facetedsearch’ module flaw allows unauthenticated attackers to inject objects, leading to remote code execution through a webshell. No patch is available yet, making immediate mitigation essential.
SecAlerts@SecAlertsCoDisclosure
PrestaShop’s ps_facetedsearch module is vulnerable to CVE-2026-54159, a critical PHP Object Injection that allows unauthenticated remote code execution via a crafted URL slider filter.
DailyCVE@dailycveDisclosure
A brief alert highlights a critical PHP Object Injection flaw in PrestaShop’s ps_facetedsearch module (CVE‑2026‑54159), without detail on PoC, exploitation, or remediation.