CVE-2026-54159
The PrestaShop ps_facetedsearch module (versions 3.0.0 through 4.0.3) insufficiently validates slider filter values taken from the URL, allowing an unauthenticated attacker to inject a malicious serialized PHP object into the module's cache. When the object is later deserialized, a gadget chain can write an arbitrary PHP file (webshell) in the module directory, leading to remote code execution. The issue is resolved in version 4.0.4.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of the PrestaShop ps_facetedsearch module versions 3.0.0 to 4.0.3.
Real-world impact
An attacker can achieve full control of the web server by uploading and executing a webshell.
Why this severity
CVSS v3.1 base score of 10 (Critical) due to network‑adjacent, low‑complexity attack requiring no privileges or user interaction, with high impacts to confidentiality, integrity, and availability.
What to do about it
- 01Upgrade the ps_facetedsearch module to version 4.0.4 or later.
Fix information comes from the NVD description which states the issue is fixed in version 4.0.4.
Timeline
- Jul 17, 2026 · 16d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.