CVE-2026-33673: PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
(updated )
Multiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-33673 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →