<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 04:41:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-255270</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255270</link>
      <description>EUVD-2026-255270</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255270</guid>
    </item>
    <item>
      <title>fkie_cve-2025-61924</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-61924</link>
      <description>&lt;p&gt;PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-61924</guid>
    </item>
    <item>
      <title>GHSA-wvpg-4wrh-5889 — PrestaShop Checkout Target PayPal merchant account hijacking from backoffice</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wvpg-4wrh-5889</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: prestashop/ps_checkout&lt;/p&gt;
&lt;p&gt;### Impact
Wrong usage of the PHP `array_search()` allows bypass of validation.&lt;/p&gt;
&lt;p&gt;### Patches
The problem has been patched in versions:
- v4.4.1 for PrestaShop 1.7 (build number: 7.4.4.1)
- v4.4.1 for PrestaShop 8 (build number: 8.4.4.1)
- v5.0.5 for PrestaShop 1.7 (build number: 7.5.0.5)
- v5.0.5 for PrestaShop 8 (build number: 8.5.0.5)
- v5.0.5 for PrestaShop 9 (build number: 9.5.0.5)&lt;/p&gt;
&lt;p&gt;Read the [Versioning policy](https://github.com/PrestaShopCorp/ps_checkout/wiki/Versioning) to learn more about the build number.&lt;/p&gt;
&lt;p&gt;### Credits
[Léo CUNÉAZ](https://github.com/inem0o) reported this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: prestashop/ps_checkout&lt;/p&gt;
&lt;p&gt;### Impact
Wrong usage of the PHP `array_search()` allows bypass of validation.&lt;/p&gt;
&lt;p&gt;### Patches
The problem has been patched in versions:
- v4.4.1 for PrestaShop 1.7 (build number: 7.4.4.1)
- v4.4.1 for PrestaShop 8 (build number: 8.4.4.1)
- v5.0.5 for PrestaShop 1.7 (build number: 7.5.0.5)
- v5.0.5 for PrestaShop 8 (build number: 8.5.0.5)
- v5.0.5 for PrestaShop 9 (build number: 9.5.0.5)&lt;/p&gt;
&lt;p&gt;Read the [Versioning policy](https://github.com/PrestaShopCorp/ps_checkout/wiki/Versioning) to learn more about the build number.&lt;/p&gt;
&lt;p&gt;### Credits
[Léo CUNÉAZ](https://github.com/inem0o) reported this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wvpg-4wrh-5889</guid>
    </item>
  </channel>
</rss>
