This is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view.
An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover.
Patched in PrestaShop 8.2.6 and 9.1.1.
None.
anthropic@doyensec.com) in collaboration with Anthropic Research.{
"github_reviewed": true,
"github_reviewed_at": "2026-05-08T16:54:22Z",
"cwe_ids": [
"CWE-79"
],
"severity": "CRITICAL",
"nvd_published_at": null
}