tag
E-Commerce
PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)
The PrestaShop Checkout module exposes an ExpressCheckout endpoint (/module/pscheckout/ExpressCheckout) that is meant to handle PayPal Express Checkout order confirmation callbacks. Versions of the module prior to 5.0.5 fail to properly verify that the caller…
Saleor GraphQL IDOR — Unauthenticated Order PII Exfiltration (CVE-2026-24136)
Saleor exposes a GraphQL order(id: $id) query used to fetch detailed order information by its global Relay ID. In affected versions this resolver performs no authorization check, so any unauthenticated caller who obtains (or guesses) an order's global ID can…
Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247)
CVE-2026-45247 is a PHP object injection / insecure deserialization vulnerability in Mirasvit's Full Page Cache Warmer extension for Magento 2. The extension processes attacker-controlled data from the CacheWarmer cookie and passes it directly to PHP's native…