CVE-2026-85520
Published 29 September 2026 · tracked since 29 September 2026
Description
Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the la
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-95520 HIGH 7.1
- CVE-2026-66083
- CVE-2026-102495
- CVE-2026-102496
- CVE-2026-102497
- CVE-2026-8937 MEDIUM 4.3
- CVE-2026-81862
- CVE-2026-81914
- CVE-2026-81930 MEDIUM 6.3
- CVE-2026-84739 HIGH 8.7