CVE-2026-14846

In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation of the ‘Alias’ parameter in the ‘Update your address’ function. This flaw allows an attacker to inject malicious expressions that are executed when the information is exported using the ‘Get my data in CSV’ tool. Successful exploitation of this vulnerability could facilitate unauthorised access to the victim’s personal data.
CVSS

No CVSS.

Configurations

No configuration.

History

13 Jul 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 10:16

Updated : 2026-07-13 18:05


NVD link : CVE-2026-14846

Mitre link : CVE-2026-14846

CVE.ORG link : CVE-2026-14846


JSON object : View

Products Affected

No product.

CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File