<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T07:15:20.172070+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-255309</id>
    <title>EUVD-2026-255309</title>
    <updated>2026-10-08T07:15:20.228104+00:00</updated>
    <content>EUVD-2026-255309</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-255309"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-61922</id>
    <title>fkie_cve-2025-61922</title>
    <updated>2026-10-08T07:15:20.228144+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-61922"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-54hq-mf6h-48xh</id>
    <title>GHSA-54hq-mf6h-48xh — PrestaShop Checkout allows customer account takeover via email</title>
    <updated>2026-10-08T07:15:20.228177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: prestashop/ps_checkout</p>
<p># Impact
Missing validation on Express Checkout feature allows silent log-in</p>
<p>## Affected versions</p>
<p>The issue was introduced in PrestaShop Checkout 1.3.0 .</p>
<p>All versions above 1.3.0 are vulnerable except of course the patch versions published on 16/10/2025: 7.4.4.1, 8.4.4.1, 7.5.0.5, 8.5.0.5, 9.5.0.5</p>
<p># Patches
The problem has been patched in versions</p>
<p>- v4.4.1 for PrestaShop 1.7 (build number: 7.4.4.1)
- v4.4.1 for PrestaShop 8 (build number: 8.4.4.1)
- v5.0.5 for PrestaShop 1.7 (build number: 7.5.0.5)
- v5.0.5 for PrestaShop 8 (build number: 8.5.0.5)
- v5.0.5 for PrestaShop 9 (build number: 9.5.0.5)</p>
<p>Read our [Versioning policy](https://github.com/PrestaShopCorp/ps_checkout/wiki/Versioning) to learn more about our build numbers and versions of PrestaShop Checkout</p>
<p># Credits
We would like to thank [Léo CUNÉAZ](https://github.com/inem0o) for reporting the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-54hq-mf6h-48xh"/>
  </entry>
</feed>
