Vulnary
← back to the feed
Critical· 10official fix available

CVE-2026-54159

The PrestaShop ps_facetedsearch module (versions 3.0.0 through 4.0.3) insufficiently validates slider filter values taken from the URL, allowing an unauthenticated attacker to inject a malicious serialized PHP object into the module's cache. When the object is later deserialized, a gadget chain can write an arbitrary PHP file (webshell) in the module directory, leading to remote code execution. The issue is resolved in version 4.0.4.

publishedJul 17, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
10
critical · how bad it is
exploitation · epss
<1%
33th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 1, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Users of the PrestaShop ps_facetedsearch module versions 3.0.0 to 4.0.3.

02

Real-world impact

An attacker can achieve full control of the web server by uploading and executing a webshell.

03

Why this severity

CVSS v3.1 base score of 10 (Critical) due to network‑adjacent, low‑complexity attack requiring no privileges or user interaction, with high impacts to confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade the ps_facetedsearch module to version 4.0.4 or later.

Fix information comes from the NVD description which states the issue is fixed in version 4.0.4.

05

Timeline

  1. Jul 17, 2026 · 16d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 23, 2026 · 10d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →