We found results for “”
CVE-2026-25597
Good to know:
Date: February 4, 2026
Impact A time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. Patches 8.2.4 and 9.0.3 Workarounds none References Found by Lam Yiu Tung
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Observable Timing Discrepancy
CWE-208Top Fix
Upgrade Version
Upgrade to version prestashop/prestashop - 9.0.3;prestashop/prestashop - 8.2.4
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


