A time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times.
8.2.4 and 9.0.3
none
Found by Lam Yiu Tung
{
"github_reviewed_at": "2026-02-03T21:13:02Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-208"
],
"nvd_published_at": "2026-02-06T21:16:17Z",
"severity": "MODERATE"
}